CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-49809
6.5 MEDIUM

Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low …

Aug 26, 2026
CVE-2026-47848
6.1 MEDIUM

In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client may leak credentials. In order for this to happen, …

Aug 26, 2026
CVE-2026-47844
5.3 MEDIUM

In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for this to happen, the server must be …

Aug 26, 2026
CVE-2026-47843
3.7 LOW

In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrectly reuse a previously configured DNS resolver. Reactor Netty 1.3.0 - …

Aug 26, 2026
CVE-2026-47842
6.5 MEDIUM

Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as the encryption mode encrypt data with AES/CBC using …

Aug 26, 2026
CVE-2026-47834
4.8 MEDIUM

Spring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from untrusted sources. Spring Data JPA 4.1.0 Spring Data JPA …

Aug 26, 2026
CVE-2026-46371
6.5 MEDIUM

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) …

Aug 26, 2026
CVE-2026-46370
6.5 MEDIUM

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an …

Aug 26, 2026
CVE-2026-46369
7.5 HIGH

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound …

Aug 26, 2026
CVE-2026-26449
7.5 HIGH

In Stomper 5e2741e when a client sends a SEND frame missing the destination header field, the server triggers a null pointer dereference (or access to …

Aug 26, 2026
CVE-2026-26448
9.8 CRITICAL

Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection, and subsequently another client (or a later …

Aug 26, 2026
CVE-2026-26447
7.5 HIGH

Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeatedly issues SUBSCRIBE commands for the same destination over one connection and then closes that …

Aug 26, 2026
CVE-2026-26446
7.5 HIGH

Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was already closed by the peer, …

Aug 26, 2026
CVE-2026-26445

stomper 5e2741e is vulnerable to Denial of Service. A malicious client can send partial STOMP frames and keep the TCP connections open, which, combined with …

Aug 26, 2026
CVE-2025-70340
6.5 MEDIUM

A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms comments functionality. An authenticated customer user can manipulate …

Aug 26, 2026
CVE-2025-70293
9.8 CRITICAL

An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation …

Aug 26, 2026
CVE-2025-70290
9.8 CRITICAL

An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. …

Aug 26, 2026
CVE-2026-79940
5.9 MEDIUM

Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Control vulnerability. An unauthenticated attacker with remote access …

Aug 26, 2026
CVE-2026-75466
6.5 MEDIUM

libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexed-color PNG image with a non-gray palette through tj3LoadImage12() or …

Aug 26, 2026
CVE-2026-75325
9.8 CRITICAL

DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters.

Aug 26, 2026
CVE-2026-71171
7.2 HIGH

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in …

Aug 26, 2026
CVE-2026-70419
9.1 CRITICAL

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A …

Aug 26, 2026
CVE-2026-63179
4.9 MEDIUM

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, authenticated backend users can disclose …

Aug 26, 2026
CVE-2026-51106
9.3 CRITICAL

An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component

Aug 26, 2026
CVE-2026-48786
6.5 MEDIUM

Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/targets) returned unmasked team enroll …

Aug 26, 2026
CVE-2026-41262
4.3 MEDIUM

Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read endpoint (GET /api/latest/fleet/policies/{policy_id}) fails to verify …

Aug 26, 2026
CVE-2026-36851
7.5 HIGH

Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.

Aug 26, 2026
CVE-2026-19485

A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform …

Aug 26, 2026
CVE-2025-61165
9.8 CRITICAL

An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file.

Aug 26, 2026
CVE-2025-61164
7.5 HIGH

Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.

Aug 26, 2026
CVE-2025-61163
9.8 CRITICAL

Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin …

Aug 26, 2026
CVE-2025-61162
7.5 HIGH

Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted request to the /api/internal/v1/users/{{USER_ID}} endpoint

Aug 26, 2026
CVE-2026-76784

Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge …

Aug 26, 2026
CVE-2026-58474
8.8 HIGH

whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to …

Aug 26, 2026
CVE-2026-54256
5.4 MEDIUM

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend FileUpload form widget …

Aug 26, 2026
CVE-2026-47841
7.4 HIGH

An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store. Spring Security 7.1.0 Spring …

Aug 26, 2026
CVE-2026-47837
6.8 MEDIUM

Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This …

Aug 26, 2026
CVE-2026-47836
7.2 HIGH

The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config …

Aug 26, 2026
CVE-2026-32639
6.8 MEDIUM

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor …

Aug 26, 2026
CVE-2026-32593
5.9 MEDIUM

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is …

Aug 26, 2026
CVE-2025-56798
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication …

Aug 26, 2026
CVE-2025-29419
7.1 HIGH

CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.

Aug 26, 2026
CVE-2023-42179
9.8 CRITICAL

Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process.

Aug 26, 2026
CVE-2026-80153

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 26, 2026
CVE-2026-35445

Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend did not validate the handler …

Aug 26, 2026
CVE-2026-32258
8.1 HIGH

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor …

Aug 26, 2026
CVE-2026-32257
8.1 HIGH

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings …

Aug 26, 2026
CVE-2020-15878
8.8 HIGH

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a …

Aug 26, 2026
CVE-2020-15876
8.8 HIGH

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a …

Aug 26, 2026
CVE-2020-15874
8.8 HIGH

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the …

Aug 26, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.