CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-4482

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2021-4476

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2021-4475

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2019-25725

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2019-25715

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2017-20232

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2026-75933
7.3 HIGH

Jet Admin allows an authenticated attacker to inject JavaScript via the sign-in page's scripts and styles option. Injected script is executed in the context of …

Aug 21, 2026
CVE-2026-75932
8.6 HIGH

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute …

Aug 21, 2026
CVE-2026-75928
5.3 MEDIUM

The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in requests to users, allowing a remote, unauthenticated attacker to read information about other …

Aug 21, 2026
CVE-2026-69502
10.0 CRITICAL

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

Aug 21, 2026
CVE-2026-54789
7.5 HIGH

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to …

Aug 21, 2026
CVE-2026-49114
7.1 HIGH

In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', …

Aug 21, 2026
CVE-2026-22681
8.5 HIGH

OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the …

Aug 21, 2026
CVE-2025-3127

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2025-2795

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2026-77815
7.5 HIGH

to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic links. A symlink placed inside a scanned …

Aug 21, 2026
CVE-2026-77814
7.5 HIGH

is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent directory with path.startswith(parent_path), without appending a path separator. A directory whose name merely begins …

Aug 21, 2026
CVE-2026-77812

DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts to connect to the …

Aug 21, 2026
CVE-2026-77087
9.6 CRITICAL

Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft …

Aug 21, 2026
CVE-2026-75501
7.5 HIGH

A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router allows unauthenticated remote attackers to modify NAT port‑forwarding rules via the …

Aug 21, 2026
CVE-2026-63343
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host …

Aug 21, 2026
CVE-2026-63125
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and …

Aug 21, 2026
CVE-2026-62941
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs …

Aug 21, 2026
CVE-2026-62940
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including …

Aug 21, 2026
CVE-2026-62867
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument …

Aug 21, 2026
CVE-2026-62313
4.3 MEDIUM

Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of `restricted.containers.privilege=isolated` can be trivially bypassed, allowing a user to …

Aug 21, 2026
CVE-2026-55622
7.7 HIGH

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the …

Aug 21, 2026
CVE-2026-55621
7.7 HIGH

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing …

Aug 21, 2026
CVE-2026-50278
6.5 MEDIUM

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 have a `CIccEmbedIO::Read8()` size_t underflow. The …

Aug 21, 2026
CVE-2026-48769
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious …

Aug 21, 2026
CVE-2026-48756

Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateCustomVolumeFromBackup` in `internal/server/storage/backend.go` contains an unguarded `*time.Time` dereference on the `ExpiresAt` field …

Aug 21, 2026
CVE-2026-48755
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in …

Aug 21, 2026
CVE-2026-48754

Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).createDependentVolumesFromBackup` in `internal/server/storage/backend.go` contains a cluster of unguarded pointer derefs on every …

Aug 21, 2026
CVE-2026-48753
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows …

Aug 21, 2026
CVE-2026-48752
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read …

Aug 21, 2026
CVE-2026-48751
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on …

Aug 21, 2026
CVE-2026-48750
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the …

Aug 21, 2026
CVE-2026-48749
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary …

Aug 21, 2026
CVE-2026-47753

Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateInstanceFromBackup` in `internal/server/storage/backend.go` contains a nil-pointer dereference that an authenticated user with …

Aug 21, 2026
CVE-2026-77806
9.8 CRITICAL

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection …

Aug 21, 2026
CVE-2026-75946

A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior to 1101.2608.0.0. The vulnerability could potentially allow a local attacker …

Aug 21, 2026
CVE-2026-15580

vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse. This issue affects the PassPortal browser extension: before 3.49.6.

Aug 21, 2026
CVE-2026-77780

Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with transaction and accounting …

Aug 21, 2026
CVE-2026-77028

Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66

Aug 21, 2026
CVE-2026-76613

Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection allowed any contributor-level user to inject own content …

Aug 21, 2026
CVE-2026-76612

Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input in comments and user supplied field …

Aug 21, 2026
CVE-2026-76611

Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66.

Aug 21, 2026
CVE-2026-75115

Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Filesystem source's path filter is vulnerable to glob-based pattern …

Aug 21, 2026
CVE-2026-59654
7.5 HIGH

Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration functionality. It affects different modules and plugins of the CloudStack management …

Aug 21, 2026
CVE-2026-77776
9.1 CRITICAL

Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat …

Aug 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.