CVE Database

38680+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-60085
7.5 HIGH

PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocked_paths, blocked_imports, allow_subprocess, and allow_file_write restrictions are completely …

Jul 15, 2026
CVE-2026-58655
8.8 HIGH

The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template injection vulnerability. When rendering dynamic collection or object titles, the plugin …

Jul 15, 2026
CVE-2026-57996
8.8 HIGH

phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAdmin administrators to create SuperAdmin accounts. A delegated administrator with …

Jul 15, 2026
CVE-2026-56400
8.3 HIGH

open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute arbitrary …

Jul 15, 2026
CVE-2026-56398
7.3 HIGH

Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from …

Jul 15, 2026
CVE-2026-56339
7.5 HIGH

Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY DEFINER RPC function public.rescind_invitation that allows unauthenticated attackers to enumerate organization …

Jul 15, 2026
CVE-2026-40633
7.8 HIGH

Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker …

Jul 15, 2026
CVE-2026-57821
8.1 HIGH

A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is …

Jul 15, 2026
CVE-2026-56287
8.1 HIGH

A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sortOrder …

Jul 15, 2026
CVE-2026-35152
8.8 HIGH

A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are incorporated …

Jul 15, 2026
CVE-2026-15804
8.8 HIGH

The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands via specific parameters, thereby compromising the confidentiality, integrity, …

Jul 15, 2026
CVE-2026-15583
8.6 HIGH

A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL …

Jul 15, 2026
CVE-2026-14251
7.7 HIGH

A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped Argo CD …

Jul 15, 2026
CVE-2026-42936
7.8 HIGH

The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected …

Jul 15, 2026
CVE-2026-12512
8.6 HIGH

The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated …

Jul 15, 2026
CVE-2026-12281
8.1 HIGH

The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request …

Jul 15, 2026
CVE-2026-15752
7.3 HIGH

A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the file /api/v1/users/ of the component Backend User Endpoint. …

Jul 14, 2026
CVE-2025-56365
7.5 HIGH

A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When an InvokeCommandRequest is sent to …

Jul 14, 2026
CVE-2025-56364
7.5 HIGH

A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestinationGroupId().Value()` method is called without first checking whether a …

Jul 14, 2026
CVE-2025-56363
7.5 HIGH

A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function used in multiple clusters (Channel, Account Login, TargetNavigator, …

Jul 14, 2026
CVE-2025-56362
7.5 HIGH

A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Level Control cluster's periodic server tick logic. When a MoveToLevel …

Jul 14, 2026
CVE-2026-59733
8.8 HIGH

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces …

Jul 14, 2026
CVE-2026-54684
7.0 HIGH

jadx is a Dex to Java decompiler. From 1.5.2 to 1.5.5, a malicious .xapk file can cause jadx to write attacker-controlled archive entry contents outside …

Jul 14, 2026
CVE-2026-54572
7.5 HIGH

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks …

Jul 14, 2026
CVE-2026-50130
8.8 HIGH

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution …

Jul 14, 2026
CVE-2026-49981
8.2 HIGH

Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is …

Jul 14, 2026
CVE-2026-48808
7.5 HIGH

Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward …

Jul 14, 2026
CVE-2026-48352
7.5 HIGH

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to …

Jul 14, 2026
CVE-2026-48351
7.5 HIGH

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to …

Jul 14, 2026
CVE-2026-48337
7.8 HIGH

Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this …

Jul 14, 2026
CVE-2026-48336
7.8 HIGH

Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this …

Jul 14, 2026
CVE-2026-48335
7.8 HIGH

Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this …

Jul 14, 2026
CVE-2026-48295
7.5 HIGH

CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclosure of sensitive information. An attacker could leverage this vulnerability …

Jul 14, 2026
CVE-2026-48290
8.2 HIGH

CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current …

Jul 14, 2026
CVE-2026-48287
7.4 HIGH

CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. …

Jul 14, 2026
CVE-2026-48275
8.6 HIGH

Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Jul 14, 2026
CVE-2026-46640
8.8 HIGH

Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute syntax can concatenate an attacker-controlled string into a MacroReferenceExpression …

Jul 14, 2026
CVE-2026-46638
8.1 HIGH

Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previously loaded outside the …

Jul 14, 2026
CVE-2025-56361
7.5 HIGH

A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Level Control cluster's server tick logic (`emberAfLevelControlClusterServerTickCallback`). When a …

Jul 14, 2026
CVE-2026-61520
7.7 HIGH

Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image proxy that …

Jul 14, 2026
CVE-2026-52100
7.5 HIGH

Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to execute arbitrary code via the uploadPutHandler function

Jul 14, 2026
CVE-2026-49855
7.5 HIGH

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an …

Jul 14, 2026
CVE-2026-49853
7.7 HIGH

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, …

Jul 14, 2026
CVE-2026-49477
7.5 HIGH

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains …

Jul 14, 2026
CVE-2026-49476
7.5 HIGH

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates …

Jul 14, 2026
CVE-2026-48815
7.5 HIGH

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.verify() is accepted by the public API but …

Jul 14, 2026
CVE-2026-48370
7.8 HIGH

Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Jul 14, 2026
CVE-2026-48369
7.8 HIGH

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Jul 14, 2026
CVE-2026-48367
7.8 HIGH

After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Jul 14, 2026
CVE-2026-48366
7.8 HIGH

Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Jul 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.