CVE Database

113799+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-15793

BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this …

Jul 21, 2026
CVE-2026-15792

A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.

Jul 21, 2026
CVE-2026-15791

A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally …

Jul 21, 2026
CVE-2026-15789

A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs …

Jul 21, 2026
CVE-2026-15724
8.7 HIGH

In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary …

Jul 21, 2026
CVE-2026-15432

When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This potentially allows an attacker to use …

Jul 21, 2026
CVE-2026-15342

Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to …

Jul 21, 2026
CVE-2025-68640

The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove …

Jul 21, 2026
CVE-2026-64825
9.3 CRITICAL

Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem …

Jul 21, 2026
CVE-2026-64824
8.4 HIGH

Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths …

Jul 21, 2026
CVE-2026-64823
4.7 MEDIUM

Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_media_image() method that allows attackers controlling a Shelly device's thumb field …

Jul 21, 2026
CVE-2026-56586
3.1 LOW

HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data.

Jul 21, 2026
CVE-2026-56585
3.1 LOW

HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce …

Jul 21, 2026
CVE-2026-47396
9.8 CRITICAL

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent control API without authentication when `CALL_SERVER_TOKEN` is not …

Jul 21, 2026
CVE-2026-47395
5.5 MEDIUM

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, PraisonAI's direct-prompt CLI automatically expands `@url:` mentions …

Jul 21, 2026
CVE-2026-47394

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is incomplete. The original advisory description named four vulnerable …

Jul 21, 2026
CVE-2026-47393
9.8 CRITICAL

PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.generate_api_server_code`) that emits a Flask API server with authentication disabled by …

Jul 21, 2026
CVE-2026-47392
9.9 CRITICAL

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` in `praisonaiagents/tools/python_tools.py` (v1.6.37, subprocess sandbox mode) …

Jul 21, 2026
CVE-2026-47391
9.8 CRITICAL

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC endpoint and registers a `calculate(expression)` …

Jul 21, 2026
CVE-2026-47390
5.5 MEDIUM

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `spider_tools` URL validation can be bypassed using …

Jul 21, 2026
CVE-2026-28321
9.1 CRITICAL

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate …

Jul 21, 2026
CVE-2026-28317
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The …

Jul 21, 2026
CVE-2026-28316
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability …

Jul 21, 2026
CVE-2026-28315
6.2 MEDIUM

SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator …

Jul 21, 2026
CVE-2026-28314
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower …

Jul 21, 2026
CVE-2026-28313
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact …

Jul 21, 2026
CVE-2026-28312
9.1 CRITICAL

SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The …

Jul 21, 2026
CVE-2026-28310
9.1 CRITICAL

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. …

Jul 21, 2026
CVE-2026-28309
9.1 CRITICAL

SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in …

Jul 21, 2026
CVE-2026-28308
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The …

Jul 21, 2026
CVE-2026-28307
9.1 CRITICAL

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is …

Jul 21, 2026
CVE-2026-28306
9.1 CRITICAL

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is …

Jul 21, 2026
CVE-2026-28305
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with …

Jul 21, 2026
CVE-2026-28304
9.1 CRITICAL

SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact …

Jul 21, 2026
CVE-2026-28302
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This …

Jul 21, 2026
CVE-2026-16450
4.3 MEDIUM

A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the function getTenantId of the file /api/system/sys/dept/page of the component MyBatis-Plus Tenant Plugin. …

Jul 21, 2026
CVE-2026-16449
6.3 MEDIUM

A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The impacted element is the function OrderItem.asc/OrderItem.desc of the file /api/system/sys/dept/page of the component com.zs.sys.dept.controller.SysDeptController. …

Jul 21, 2026
CVE-2026-8933
7.8 HIGH

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap …

Jul 21, 2026
CVE-2026-65052
7.5 HIGH

Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form …

Jul 21, 2026
CVE-2026-65051
6.5 MEDIUM

Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging …

Jul 21, 2026
CVE-2026-65050
6.5 MEDIUM

Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated …

Jul 21, 2026
CVE-2026-65049
9.3 CRITICAL

Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of …

Jul 21, 2026
CVE-2026-65048
9.3 CRITICAL

Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary …

Jul 21, 2026
CVE-2026-59851
8.8 HIGH

A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for …

Jul 21, 2026
CVE-2026-59850
4.3 MEDIUM

A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated …

Jul 21, 2026
CVE-2026-59849
3.1 LOW

A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are …

Jul 21, 2026
CVE-2026-56587
3.7 LOW

HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications.

Jul 21, 2026
CVE-2026-56584
3.7 LOW

HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly …

Jul 21, 2026
CVE-2026-47122
4.2 MEDIUM

Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `shouldAcceptNewConnection:` only enforces `SUCodeSigningVerifier validateConnection:` before stage 1 completes. …

Jul 21, 2026
CVE-2026-46681

@nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility library. Prior to version 0.14.0, the _copyProps function in lib/src/object/copy.ts uses for...in to iterate over source object properties without …

Jul 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.