CVE Database

45033+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-90690
7.3 HIGH

A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected element is the function subprocess.Popen of the file hexstrike_server.py of the …

Sep 14, 2026
CVE-2026-90689
8.8 HIGH

A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthWhiteUser. Performing a manipulation of the argument webAuthWhiteUserIndex results in stack-based …

Sep 14, 2026
CVE-2026-82794
8.8 HIGH

SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by …

Sep 14, 2026
CVE-2026-82793
7.2 HIGH

Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file …

Sep 14, 2026
CVE-2026-82791
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter …

Sep 14, 2026
CVE-2026-82789
8.8 HIGH

An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by …

Sep 14, 2026
CVE-2026-82780
8.8 HIGH

Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uploaded by a remote authenticated attacker, …

Sep 14, 2026
CVE-2026-82779
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series. If this vulnerability is exploited, an …

Sep 14, 2026
CVE-2026-82777
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an …

Sep 14, 2026
CVE-2026-82774
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. …

Sep 14, 2026
CVE-2026-82772
8.8 HIGH

Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program …

Sep 14, 2026
CVE-2026-82770
8.8 HIGH

Buffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program …

Sep 14, 2026
CVE-2026-82768
8.1 HIGH

Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who …

Sep 14, 2026
CVE-2026-82766
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If this vulnerability is exploited, an arbitrary OS …

Sep 14, 2026
CVE-2026-82765
8.1 HIGH

Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be …

Sep 14, 2026
CVE-2026-82762
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If …

Sep 14, 2026
CVE-2026-68955
7.8 HIGH

The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when …

Sep 14, 2026
CVE-2023-50461
8.8 HIGH

An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated …

Sep 14, 2026
CVE-2023-46273
8.8 HIGH

Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.

Sep 14, 2026
CVE-2023-45858
8.6 HIGH

A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.

Sep 14, 2026
CVE-2023-32803
7.5 HIGH

The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue …

Sep 14, 2026
CVE-2023-28148
7.2 HIGH

A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.

Sep 14, 2026
CVE-2026-90620
7.3 HIGH

A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is an unknown function of the file hexstrike_server.py of the component …

Sep 14, 2026
CVE-2026-90619
7.3 HIGH

A vulnerability has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. Impacted is an unknown function of the file hexstrike_server.py of the component Execute …

Sep 14, 2026
CVE-2026-90618
7.3 HIGH

A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the function LocalRuntime.execute_command of the file runtime/runtime.py of the component LocalRuntime. …

Sep 14, 2026
CVE-2026-90617
7.3 HIGH

A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This vulnerability affects the function run_task of the file interface/main.py of the component MCP HTTP …

Sep 14, 2026
CVE-2026-33963
7.5 HIGH

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs …

Sep 14, 2026
CVE-2026-31278
7.7 HIGH

An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service …

Sep 14, 2026
CVE-2026-23789
7.8 HIGH

An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, …

Sep 14, 2026
CVE-2026-90603
7.3 HIGH

A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component …

Sep 13, 2026
CVE-2026-90601
7.3 HIGH

A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The …

Sep 13, 2026
CVE-2026-15891
7.5 HIGH

The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the …

Sep 13, 2026
CVE-2026-90593
7.3 HIGH

A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width …

Sep 13, 2026
CVE-2026-88802
7.5 HIGH

The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or …

Sep 13, 2026
CVE-2026-88793
8.8 HIGH

The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a …

Sep 13, 2026
CVE-2026-85129
8.8 HIGH

The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the …

Sep 13, 2026
CVE-2026-74933
8.8 HIGH

The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored …

Sep 13, 2026
CVE-2026-37008
8.1 HIGH

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module …

Sep 13, 2026
CVE-2026-36453
7.4 HIGH

Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.

Sep 13, 2026
CVE-2026-29811
7.7 HIGH

CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") …

Sep 13, 2026
CVE-2026-90579
7.3 HIGH

A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key of the file core/cat/factory/custom_auth_handler.py. The manipulation of …

Sep 13, 2026
CVE-2026-90566
7.3 HIGH

A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the …

Sep 13, 2026
CVE-2026-90526
7.3 HIGH

A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unknown function of the file /bilal/save_class.php. The manipulation …

Sep 13, 2026
CVE-2026-90524
7.3 HIGH

A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing …

Sep 13, 2026
CVE-2026-90523
7.3 HIGH

A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User …

Sep 13, 2026
CVE-2026-90783
7.8 HIGH

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can …

Sep 13, 2026
CVE-2026-90522
7.3 HIGH

A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This …

Sep 13, 2026
CVE-2026-90780
7.5 HIGH

SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated …

Sep 13, 2026
CVE-2026-90779
7.5 HIGH

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can …

Sep 13, 2026
CVE-2026-90778
7.5 HIGH

SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated …

Sep 13, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.