CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-43657
3.3 LOW

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5. A malicious app may be able to …

Aug 25, 2026
CVE-2026-80050
6.5 MEDIUM

ContiNew Admin fails to apply file-upload permission checks or file-type allowlist validation to multipart upload endpoints, allowing authenticated users to store files with arbitrary extensions. …

Aug 25, 2026
CVE-2026-80049
8.8 HIGH

Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. AuthorizationServerHandler copies recognised identifiers out of the raw JSON …

Aug 25, 2026
CVE-2026-79788
7.1 HIGH

In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required before_action on `defined?(Dradis::Pro)`, a constant that is never defined in CE, so the authorization …

Aug 25, 2026
CVE-2026-79787
9.8 CRITICAL

Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can …

Aug 25, 2026
CVE-2026-79786
7.1 HIGH

Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. …

Aug 25, 2026
CVE-2026-78379
8.1 HIGH

Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute …

Aug 25, 2026
CVE-2026-65979

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.12, the …

Aug 25, 2026
CVE-2026-62986
4.3 MEDIUM

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 …

Aug 25, 2026
CVE-2026-61555
5.5 MEDIUM

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through …

Aug 25, 2026
CVE-2026-59985
5.5 MEDIUM

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.2.0 through 3.2.10, 3.3.0 …

Aug 25, 2026
CVE-2026-55663
5.6 MEDIUM

mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, …

Aug 25, 2026
CVE-2026-55620
7.5 HIGH

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to …

Aug 25, 2026
CVE-2026-55619
5.3 MEDIUM

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to …

Aug 25, 2026
CVE-2026-55618
6.5 MEDIUM

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to …

Aug 25, 2026
CVE-2026-55609
7.1 HIGH

sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear time. Prior to consciousness-explorer 1.1.2 and sublinear-time-solver 1.6.0, the export_state …

Aug 25, 2026
CVE-2026-80051

github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validate that a scalar variable value matches its declared type. The built-in coerceString and coerceBool functions (scalars.go) …

Aug 25, 2026
CVE-2026-79992
7.8 HIGH

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login …

Aug 25, 2026
CVE-2026-76198
5.5 MEDIUM

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability …

Aug 25, 2026
CVE-2026-76197
10.0 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result …

Aug 25, 2026
CVE-2026-76195
10.0 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result …

Aug 25, 2026
CVE-2026-76193
10.0 CRITICAL

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the …

Aug 25, 2026
CVE-2026-76189
6.2 MEDIUM

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this …

Aug 25, 2026
CVE-2026-75770
7.8 HIGH

Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Aug 25, 2026
CVE-2026-75769
7.8 HIGH

Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-75768
7.8 HIGH

Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-75767
7.8 HIGH

Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-75766
7.8 HIGH

Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-75752
5.5 MEDIUM

Substance3D - Painter is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to …

Aug 25, 2026
CVE-2026-75750
7.8 HIGH

Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-75749
7.8 HIGH

Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Aug 25, 2026
CVE-2026-71564
7.8 HIGH

Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Aug 25, 2026
CVE-2026-71444
6.2 MEDIUM

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this …

Aug 25, 2026
CVE-2026-71443
7.5 HIGH

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to …

Aug 25, 2026
CVE-2026-71442
7.5 HIGH

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this …

Aug 25, 2026
CVE-2026-71441
5.5 MEDIUM

Illustrator is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive …

Aug 25, 2026
CVE-2026-71399
7.8 HIGH

Adobe XD is affected by a Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. An attacker …

Aug 25, 2026
CVE-2026-71382
7.8 HIGH

Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Aug 25, 2026
CVE-2026-71360
7.5 HIGH

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust …

Aug 25, 2026
CVE-2026-59984
5.5 MEDIUM

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.1.0 through 3.2.10, 3.3.0 …

Aug 25, 2026
CVE-2026-59983
5.5 MEDIUM

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through …

Aug 25, 2026
CVE-2026-59982
7.1 HIGH

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through …

Aug 25, 2026
CVE-2026-55637

genieacs-mcp is an MCP server for GenieACS written in Go. Prior to 0.3.2, the Streamable HTTP transport in cmd/server/main.go creates an unauthenticated /mcp listener on …

Aug 25, 2026
CVE-2026-55623

Rejected reason: This CVE is a duplicate of another CVE.

Aug 25, 2026
CVE-2026-55419
5.3 MEDIUM

Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8.2, the Reachy Mini daemon exposes the /api/media/sounds/upload endpoint implemented by the upload_sound …

Aug 25, 2026
CVE-2026-48433
7.8 HIGH

Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-48432
7.8 HIGH

Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-48431
7.8 HIGH

Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-48430
7.8 HIGH

Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-48429
5.5 MEDIUM

Substance3D - Designer is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to …

Aug 25, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.