CVE Database

113799+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-16448
6.3 MEDIUM

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 …

Jul 21, 2026
CVE-2026-15226
8.4 HIGH

A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default seccomp security templates generated by the engine …

Jul 21, 2026
CVE-2026-11876
5.0 MEDIUM

In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/stack` endpoint (`get_deployed_stack`) lacks proper RBAC authorization checks, allowing any authenticated user to enumerate all deployed stacks across all …

Jul 21, 2026
CVE-2024-5300
5.6 MEDIUM

An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd …

Jul 21, 2026
CVE-2026-9499

An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NUL-terminated (for example, …

Jul 21, 2026
CVE-2026-59848
5.3 MEDIUM

A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded …

Jul 21, 2026
CVE-2026-59847
5.9 MEDIUM

A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker …

Jul 21, 2026
CVE-2026-47121
6.1 MEDIUM

Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `relativePath.pathComponents containsObject:@".."` and rejects writes whose immediate parent directory IS itself …

Jul 21, 2026
CVE-2026-16447
7.3 HIGH

A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument Filedata[] leads …

Jul 21, 2026
CVE-2025-66390

In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the registration flow …

Jul 21, 2026
CVE-2026-8285
4.3 MEDIUM

Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. FlexCity allows Excessive Allocation. This issue affects FlexCity: from 5.536.0 through 11052026.

Jul 21, 2026
CVE-2026-8284
6.1 MEDIUM

URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data Manipulation. This issue affects FlexCity: from 5.536.0 through 11052026.

Jul 21, 2026
CVE-2026-6792
6.5 MEDIUM

Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCity: from 5.536.0 through 11052026.

Jul 21, 2026
CVE-2026-59846
3.9 LOW

A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended …

Jul 21, 2026
CVE-2026-16445
7.5 HIGH

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as …

Jul 21, 2026
CVE-2026-16412
9.8 CRITICAL

Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with …

Jul 21, 2026
CVE-2026-16411
9.8 CRITICAL

Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of …

Jul 21, 2026
CVE-2026-16410

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16409

Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16408
9.8 CRITICAL

Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16407

Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16406
9.1 CRITICAL

Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16405
7.5 HIGH

Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16404

Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16403

Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16402

Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16401

Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16400

Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16399

Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16398

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16397
6.5 MEDIUM

Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16396

Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16395
9.8 CRITICAL

Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16394
9.1 CRITICAL

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16393

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16392

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16391

Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16390

Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16389

Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16388

Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16387

Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16386

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16385

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16384

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16383

Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16382

Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16381

Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16380

Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16379

Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16378

Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.