CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-55850

Element Web is a Matrix web client built using the Matrix React SDK. Prior to 1.12.22, EmbeddedPage in apps/web/src/components/structures/EmbeddedPage.tsx renders homeserver-supplied homepage content through dangerouslySetInnerHTML …

Aug 21, 2026
CVE-2026-54682
8.2 HIGH

DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync …

Aug 21, 2026
CVE-2026-54681
4.1 MEDIUM

DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, the VisitEmojiAsync method in DiscordChatExporter.Core/Exporting/HtmlMarkdownVisitor.cs interpolates emoji.Name into the alt attribute and emoji.Code into …

Aug 21, 2026
CVE-2026-54134

OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, OctoPrint's custom Tornado upload handler and Flask with Werkzeug parse …

Aug 21, 2026
CVE-2026-54073

VeraCrypt provides disk encryption with strong security based on TrueCrypt. From 1.26.6 until 1.26.29, file-hosted hidden volume creation forces quick format and the FormatNoFs function …

Aug 21, 2026
CVE-2026-54071
7.8 HIGH

BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF parser in babeldoc/pdfminer/cmapdb.py deserializes untrusted pickle data when CMapDB._load_data() loads CMap files. PDF-controlled …

Aug 21, 2026
CVE-2026-53762
6.2 MEDIUM

VeraCrypt provides disk encryption with strong security based on TrueCrypt. Prior to 1.26.29, non-default builds created with WOLFCRYPT=1 and WOLFCRYPT_BACKEND route SHA-256 and SHA-512 volume-header …

Aug 21, 2026
CVE-2026-35163

OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command notification popups use PNotify rendering for printer-controlled payload.command …

Aug 21, 2026
CVE-2026-77237
6.5 MEDIUM

Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with configUSE_QUEUE_SETS=1 to read privileged kernel …

Aug 21, 2026
CVE-2026-77236
7.3 HIGH

Missing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11.3.1 might allow local users to corrupt secure-world heap metadata via an out-of-bounds write …

Aug 21, 2026
CVE-2026-77235
7.3 HIGH

Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local users to cause a use-after-free condition in secure-world memory …

Aug 21, 2026
CVE-2026-77234
8.8 HIGH

Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this …

Aug 21, 2026
CVE-2026-71862
7.5 HIGH

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 …

Aug 21, 2026
CVE-2026-71494

Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, internal/hcl/remote_variables_loader.go and related Terraform Cloud, remote-plan, and Terragrunt registry request …

Aug 21, 2026
CVE-2026-71493

Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, the readFile, pathExists, isDir, and matchPaths template functions in internal/config/template/parser.go …

Aug 21, 2026
CVE-2026-70656
4.9 MEDIUM

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.5.1 …

Aug 21, 2026
CVE-2026-62677
8.8 HIGH

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authenticated user can upload a session-scoped agent bundle …

Aug 21, 2026
CVE-2026-62676
7.1 HIGH

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shared shell-command parser in omnigent/policies/builtins/_shell.py fails to recognize …

Aug 21, 2026
CVE-2026-62675
8.8 HIGH

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts an authenticated user's agent bundle …

Aug 21, 2026
CVE-2026-62674
9.0 CRITICAL

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but …

Aug 21, 2026
CVE-2026-55241
7.5 HIGH

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to …

Aug 21, 2026
CVE-2026-41451
7.8 HIGH

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_artifact.sh where usernames and home directories …

Aug 21, 2026
CVE-2026-41450
7.8 HIGH

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_collector function where foreach command output lines are substituted directly …

Aug 21, 2026
CVE-2026-41449
7.8 HIGH

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_command function that allows attackers to execute arbitrary commands by …

Aug 21, 2026
CVE-2026-27875

Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded …

Aug 21, 2026
CVE-2026-17252

A stack-based out-of-bounds write vulnerability exists in the login request handling functionality of the administrative web interface of TP-Link TL-MR6400 v7 routers. An unauthenticated adjacent …

Aug 21, 2026
CVE-2026-17251

A NULL pointer dereference vulnerability exists in the HTTP request parsing functionality of TL-MR6400 v7. An unauthenticated remote attacker can trigger the vulnerability by sending …

Aug 21, 2026
CVE-2026-17250

A stack-based buffer overflow vulnerability exists in the firmware update functionality of TL-MR6400 v7 due to unsafe processing of attacker-controlled metadata within a firmware image. …

Aug 21, 2026
CVE-2026-9324

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2026-9321

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2026-9244

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2026-9012

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2026-74583
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_route: fix fastmap use-after-free on filter The route4 classifier maintains a 16-slot fastmap cache …

Aug 21, 2026
CVE-2026-74582
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: packet: use consistent hard_header_len in non-ring send paths packet_snd() reads dev->hard_header_len multiple times while allocating …

Aug 21, 2026
CVE-2026-74581
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(), but …

Aug 21, 2026
CVE-2026-74580
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: vhost: reset the vring metadata cache on vring reconfiguration vq->meta_iotlb[] caches the vhost_iotlb_map that backs …

Aug 21, 2026
CVE-2026-69701

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2026-69099

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2026-63726

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2026-57835

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2026-53991

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2026-53974

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2026-39909
8.1 HIGH

llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler that allows unauthenticated remote attackers to achieve arbitrary read and write access …

Aug 21, 2026
CVE-2026-11938

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2026-11902

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2026-11830

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2026-11427

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2023-7344

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2023-7336

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2023-7310

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.