CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-72704
6.3 MEDIUM

The guard checker in Rocq Prover does not recheck the recursive tree representation of an inductive type parameter after that parameter has been changed by …

Aug 24, 2026
CVE-2026-72703
6.3 MEDIUM

The guard checker in Rocq Prover treats a parameter of a nested mutual fixpoint as uniform without examining calls between the different bodies of that …

Aug 24, 2026
CVE-2026-71511
6.5 MEDIUM

Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticated attackers with member-read rights to retrieve bcrypt password …

Aug 24, 2026
CVE-2026-71510
6.5 MEDIUM

Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by …

Aug 24, 2026
CVE-2026-63693
6.6 MEDIUM

Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this …

Aug 24, 2026
CVE-2026-61419
7.8 HIGH

Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, …

Aug 24, 2026
CVE-2020-37268
6.3 MEDIUM

Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition reaches the caller through Parameter Inline in …

Aug 24, 2026
CVE-2026-78541

A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store …

Aug 24, 2026
CVE-2026-78417
4.3 MEDIUM

Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to …

Aug 24, 2026
CVE-2026-75371
7.5 HIGH

An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-proximate attackers with UART access to cause a Denial …

Aug 24, 2026
CVE-2026-75370
6.5 MEDIUM

An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via …

Aug 24, 2026
CVE-2026-71832
6.2 MEDIUM

Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial …

Aug 24, 2026
CVE-2026-71509
6.5 MEDIUM

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint that allows authenticated attackers with expense-creation rights to bypass …

Aug 24, 2026
CVE-2026-71508
6.5 MEDIUM

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields …

Aug 24, 2026
CVE-2026-71507
6.5 MEDIUM

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation …

Aug 24, 2026
CVE-2026-71506
8.1 HIGH

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete …

Aug 24, 2026
CVE-2026-71505
7.1 HIGH

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation …

Aug 24, 2026
CVE-2026-71504
8.1 HIGH

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of …

Aug 24, 2026
CVE-2026-71503
6.1 MEDIUM

Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding …

Aug 24, 2026
CVE-2026-40877
8.7 HIGH

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which …

Aug 24, 2026
CVE-2026-39975

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code …

Aug 24, 2026
CVE-2026-30864
8.9 HIGH

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. …

Aug 24, 2026
CVE-2026-13081

Rejected reason: Red Hat is not the CNA for PHP. CVE was reserved in error; the appropriate CNA should assign CVE IDs for these vulnerabilities.

Aug 24, 2026
CVE-2026-13047

Rejected reason: Red Hat is not the CNA for PHP. CVE was reserved in error; the appropriate CNA should assign CVE IDs for these vulnerabilities.

Aug 24, 2026
CVE-2025-26238
8.1 HIGH

In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code.

Aug 24, 2026
CVE-2025-26237
8.1 HIGH

D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can be exploited to run arbitrary commands.

Aug 24, 2026
CVE-2026-9254

An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering …

Aug 24, 2026
CVE-2026-78475
6.1 MEDIUM

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array …

Aug 24, 2026
CVE-2026-76838
8.5 HIGH

Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule.php resolves the hostname with gethostbyname() and rejects …

Aug 24, 2026
CVE-2026-76837
6.4 MEDIUM

Baserow interpolates a user's display name into the rich-text mention markup without HTML encoding. PATCH /api/user/account/ stores the first_name value verbatim, and the mention renderer …

Aug 24, 2026
CVE-2026-76836
8.8 HIGH

AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in backend/src/Entity/Station.php is annotated …

Aug 24, 2026
CVE-2026-76835
9.1 CRITICAL

OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the …

Aug 24, 2026
CVE-2026-76073
8.8 HIGH

Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset …

Aug 24, 2026
CVE-2026-76072
7.4 HIGH

The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands when running unattended. In headless mode and auto mode the …

Aug 24, 2026
CVE-2026-71982

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 24, 2026
CVE-2026-71943
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerability is caused by insufficient filtering of the username and password …

Aug 24, 2026
CVE-2026-71942
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a …

Aug 24, 2026
CVE-2026-71941
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a …

Aug 24, 2026
CVE-2026-71940
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE function. The vulnerability is caused by copying the name field into …

Aug 24, 2026
CVE-2026-71939
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. The vulnerability is caused by copying the name field into …

Aug 24, 2026
CVE-2026-71938
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnerability is caused by unsafe copying of the portList field into …

Aug 24, 2026
CVE-2026-71937
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. The vulnerability is caused by repeated concatenation of the start_date, start_time, duration_time, …

Aug 24, 2026
CVE-2026-71936
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability is caused by unsafe concatenation of split valueN data into …

Aug 24, 2026
CVE-2026-71935
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnerability is caused by repeated string concatenation of the pathN, valueN, …

Aug 24, 2026
CVE-2026-71934
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability is caused by missing length checks when the host, count, …

Aug 24, 2026
CVE-2026-71933
9.1 CRITICAL

Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger …

Aug 24, 2026
CVE-2026-71932
4.9 MEDIUM

Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A …

Aug 24, 2026
CVE-2026-71931
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerability is caused by insufficient filtering before the filename field is …

Aug 24, 2026
CVE-2026-71930
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability is caused by insufficient filtering of the username and password …

Aug 24, 2026
CVE-2026-71929
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerability is caused by insufficient filtering of the username and password …

Aug 24, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.