CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-48428
7.8 HIGH

Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-48427
7.8 HIGH

Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Aug 25, 2026
CVE-2026-48426
7.8 HIGH

Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Aug 25, 2026
CVE-2026-48425
7.8 HIGH

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-48424
7.8 HIGH

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-48423
7.8 HIGH

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-48422
7.8 HIGH

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-48421
7.8 HIGH

Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Aug 25, 2026
CVE-2026-48420
7.8 HIGH

Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Aug 25, 2026
CVE-2026-48419
7.8 HIGH

Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Aug 25, 2026
CVE-2026-48418
7.8 HIGH

Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Aug 25, 2026
CVE-2026-48417
7.8 HIGH

Substance3D - Sampler is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-26211
4.8 MEDIUM

Ekushey Project Manager CRM stores the administrator-configured system name and writes it to the login page without output encoding. The value is emitted in three …

Aug 25, 2026
CVE-2026-78468
6.5 MEDIUM

The FluentCRM Pro – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin for WordPress is vulnerable to SQL Injection in …

Aug 25, 2026
CVE-2026-75498
7.2 HIGH

Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to …

Aug 25, 2026
CVE-2026-75497
7.2 HIGH

Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to …

Aug 25, 2026
CVE-2026-75496
7.2 HIGH

Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, …

Aug 25, 2026
CVE-2026-64204
7.8 HIGH

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an …

Aug 25, 2026
CVE-2026-64203
7.8 HIGH

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an …

Aug 25, 2026
CVE-2026-64202
7.8 HIGH

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an …

Aug 25, 2026
CVE-2026-64201
7.8 HIGH

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an …

Aug 25, 2026
CVE-2026-59189
7.1 HIGH

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In OpenEXRUtil versions 3.3.0 through 3.3.12 …

Aug 25, 2026
CVE-2026-59187
7.1 HIGH

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.3.0 through 3.3.12 and …

Aug 25, 2026
CVE-2026-59186
7.1 HIGH

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through …

Aug 25, 2026
CVE-2026-59184
7.1 HIGH

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, …

Aug 25, 2026
CVE-2026-55585
8.8 HIGH

QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, schemas, and agent state before production execution. Prior to 5.1.2, …

Aug 25, 2026
CVE-2026-55571
8.2 HIGH

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to 1.0.4, LiveViewConsumer.handle_mount sends a `{"type":"navigate","to":...}` frame when login_required, permission_required, or a …

Aug 25, 2026
CVE-2026-55557

browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents. Prior to 0.8.2, browser_download writes a fetched response body to join(save_dir, filename) without validating the …

Aug 25, 2026
CVE-2026-55553
7.5 HIGH

urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prior to 4.9.1 and 2.44.1, urllib follows redirects through …

Aug 25, 2026
CVE-2026-47626
8.2 HIGH

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit …

Aug 25, 2026
CVE-2026-47624
6.0 MEDIUM

NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of this vulnerability …

Aug 25, 2026
CVE-2026-24263
8.2 HIGH

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference. A successful …

Aug 25, 2026
CVE-2026-24262
8.2 HIGH

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit …

Aug 25, 2026
CVE-2026-24225
6.0 MEDIUM

NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read. A successful exploit …

Aug 25, 2026
CVE-2026-24170
8.8 HIGH

NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticated user could cause improper authentication by sending specially crafted HTTP …

Aug 25, 2026
CVE-2026-24169
8.0 HIGH

NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated user with low privileges could inject code by sending a specially …

Aug 25, 2026
CVE-2026-24168
6.8 MEDIUM

NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker with administrative privileges may cause command injection by sending crafted API …

Aug 25, 2026
CVE-2026-24167
6.8 MEDIUM

NVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authenticated administrator could inject commands by sending a crafted API request. A …

Aug 25, 2026
CVE-2026-24166
5.1 MEDIUM

NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-coded cryptographic key to extract information. A successful …

Aug 25, 2026
CVE-2026-19913
7.5 HIGH

The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation of the ServiceUrl parameter in mwEmbedLoader.php. This parameter …

Aug 25, 2026
CVE-2026-19912

The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by unsafe data deserialization and unsanitized filesystem path construction. mwEmbedLoader.php …

Aug 25, 2026
CVE-2026-18445
6.6 MEDIUM

There is an integer overflow vulnerability resulting in an out-of-bounds write recently discovered in NI LabVIEW. This may result in information disclosure or arbitrary code …

Aug 25, 2026
CVE-2026-18444
6.6 MEDIUM

There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered in NI LabVIEW. This may result in information disclosure …

Aug 25, 2026
CVE-2026-16234
7.8 HIGH

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an …

Aug 25, 2026
CVE-2026-16233
7.8 HIGH

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an …

Aug 25, 2026
CVE-2026-13478
5.5 MEDIUM

The Zephyr ext2 filesystem driver validates the on-disk block bitmap in ext2_init_fs() (subsys/fs/ext2/ext2_impl.c) by passing fs_blocks = s_blocks_count - s_first_data_block to ext2_bitmap_count_set(). That helper (subsys/fs/ext2/ext2_bitmap.c) …

Aug 25, 2026
CVE-2026-13217
5.9 MEDIUM

The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the uid field of a CALLRESULT message. In ocpp_process_server_msg() the code …

Aug 25, 2026
CVE-2026-13216
6.1 MEDIUM

The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's PCI capability list during driver initialization. In virtio_pci_read_cap() the device-supplied capability length byte cap_len (read from PCI …

Aug 25, 2026
CVE-2026-79785
5.9 MEDIUM

X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in anylabeling/services/auto_labeling/model.py built a context with ssl._create_unverified_context() and passed it to urllib.request.urlopen, so neither the certificate chain …

Aug 25, 2026
CVE-2026-79784
8.8 HIGH

Vocos instantiates a class named by a configuration file without restricting which class may be named. instantiate_class in vocos/pretrained.py takes the class_path value from the …

Aug 25, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.