CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-59295
5.9 MEDIUM

It is possible for outbound HTTP requests using a Micrometer-instrumented client to cause a denial-of-service (DoS) condition due to an unbounded memory leak. Micrometer 1.17.0 …

Aug 24, 2026
CVE-2026-10618
5.4 MEDIUM

Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them. New in markup/internal/attributes/attributes.go converts every …

Aug 24, 2026
CVE-2026-10582
7.4 HIGH

Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the …

Aug 24, 2026
CVE-2026-78317
8.8 HIGH

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

Aug 24, 2026
CVE-2026-78316
8.8 HIGH

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

Aug 24, 2026
CVE-2026-78315
8.8 HIGH

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

Aug 24, 2026
CVE-2026-78314
8.8 HIGH

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

Aug 24, 2026
CVE-2026-75975
7.5 HIGH

fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text …

Aug 24, 2026
CVE-2026-75931
7.5 HIGH

fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a …

Aug 24, 2026
CVE-2026-75899
7.5 HIGH

fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time …

Aug 24, 2026
CVE-2026-66897
9.9 CRITICAL

A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite …

Aug 24, 2026
CVE-2026-16249

Rejected reason: This CVE ID is a duplicate of CVE-2026-15303 and was never published. Both IDs were assigned to the same vulnerability in the 6Storage …

Aug 24, 2026
CVE-2026-78321

The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone's …

Aug 24, 2026
CVE-2026-78306

DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, …

Aug 24, 2026
CVE-2026-78255

The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating the requesting client. Filenames follow a …

Aug 24, 2026
CVE-2026-77994

Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to …

Aug 24, 2026
CVE-2026-77993

Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a reflected …

Aug 24, 2026
CVE-2026-8173
5.3 MEDIUM

The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned …

Aug 24, 2026
CVE-2026-78202
7.3 HIGH

A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_settings of the file admin_class.php. The manipulation of the argument img results …

Aug 24, 2026
CVE-2026-78201
7.3 HIGH

A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the function Login of the file admin_class.php. The manipulation of the …

Aug 24, 2026
CVE-2026-78200
6.3 MEDIUM

A flaw has been found in itsourcecode Library Management System 1.0. The affected element is an unknown function of the file editbooks.php. Executing a manipulation …

Aug 24, 2026
CVE-2026-78199
7.3 HIGH

A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/view_prod.php. Performing a manipulation of …

Aug 24, 2026
CVE-2026-78198
7.3 HIGH

A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=add_to_cart. Such …

Aug 24, 2026
CVE-2026-78197
7.3 HIGH

A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /fos/admin/ajax.php?action=save_user. This manipulation of …

Aug 24, 2026
CVE-2026-78196
4.4 MEDIUM

A security flaw has been discovered in achorein expo-share-intent up to 8.0.0. This affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component Android …

Aug 24, 2026
CVE-2026-78187
3.1 LOW

A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication Page. Such manipulation of the argument lang …

Aug 24, 2026
CVE-2026-78186
4.3 MEDIUM

A flaw has been found in Open5GS up to 2.8.0. This affects an unknown function of the file src/hss/hss-cx-path.c of the component HSS. This manipulation …

Aug 24, 2026
CVE-2026-59561
7.8 HIGH

Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in …

Aug 24, 2026
CVE-2026-78213
8.7 HIGH

Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authenticated remote attackers can inject persistent malicious content into specific pages, causing arbitrary …

Aug 24, 2026
CVE-2026-78212
7.5 HIGH

4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit a Relative Path Traversal flaw to …

Aug 24, 2026
CVE-2026-78211
9.8 CRITICAL

4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb …

Aug 24, 2026
CVE-2026-78185
6.3 MEDIUM

A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/cust_edit.php. The manipulation of …

Aug 24, 2026
CVE-2026-78182
7.3 HIGH

A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300. The affected element is the function PlanController.getImmediatePlans …

Aug 24, 2026
CVE-2026-78181
7.3 HIGH

A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive#set of the component Keypath Handler. Executing a manipulation can …

Aug 24, 2026
CVE-2026-78180
7.3 HIGH

A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component …

Aug 24, 2026
CVE-2026-78179
6.3 MEDIUM

A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function SetValue of the file plugins/utils/object/SetValue.js of the component BehaviorTree Blackboard …

Aug 24, 2026
CVE-2026-19853
5.3 MEDIUM

NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a specific functionality to send emails to anyone on behalf …

Aug 24, 2026
CVE-2026-19852
6.1 MEDIUM

NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload arbitrary files, including malicious HTML files, thereby achieving effects …

Aug 24, 2026
CVE-2026-19200
8.9 HIGH

The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL …

Aug 24, 2026
CVE-2026-78178
7.3 HIGH

A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/jqxBaseFramework.extend of the file jqwidgets/jqx-all.js. This manipulation causes improperly controlled modification of …

Aug 24, 2026
CVE-2026-78177
4.5 MEDIUM

A vulnerability was found in TanStack devtools-vite 0.7.0. Affected by this issue is the function installPackage of the file packages/devtools-bundler-core/src/package-manager.ts of the component Development Devtools …

Aug 24, 2026
CVE-2026-78171
7.3 HIGH

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/processlogin.php. The …

Aug 24, 2026
CVE-2026-78170
8.8 HIGH

A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. Executing a manipulation of …

Aug 24, 2026
CVE-2026-78169
9.9 CRITICAL

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request …

Aug 24, 2026
CVE-2026-78168
9.8 CRITICAL

A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such …

Aug 24, 2026
CVE-2026-78167
10.0 CRITICAL

A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation …

Aug 24, 2026
CVE-2026-78166
6.3 MEDIUM

A security flaw has been discovered in provectus kafka-ui up to 0.7.2. The affected element is the function executeSmartFilterTest of the file kafka-ui-api/src/main/java/com/provectus/kafka/ui/controller/MessagesController.java of the …

Aug 24, 2026
CVE-2026-78209
8.2 HIGH

exceljs through 4.4.0 fails to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported …

Aug 24, 2026
CVE-2026-78208
7.5 HIGH

exceljs through 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to …

Aug 24, 2026
CVE-2026-78207
9.4 CRITICAL

exceljs through 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. …

Aug 24, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.