CVE Database

57293+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-76104
5.5 MEDIUM

Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A high privileged attacker with remote access …

Sep 16, 2026
CVE-2026-26947
6.7 MEDIUM

Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with local …

Sep 16, 2026
CVE-2026-19607
5.3 MEDIUM

A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs …

Sep 16, 2026
CVE-2026-92616
6.8 MEDIUM

FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploiting improper session …

Sep 16, 2026
CVE-2026-92570
6.5 MEDIUM

reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration files. …

Sep 16, 2026
CVE-2026-92569
4.3 MEDIUM

Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that fail to validate the clientAddress parameter. Authenticated attackers can supply arbitrary …

Sep 16, 2026
CVE-2026-92568
5.4 MEDIUM

MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary HTTP …

Sep 16, 2026
CVE-2026-92567
6.5 MEDIUM

TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form …

Sep 16, 2026
CVE-2026-92565
5.3 MEDIUM

Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers. Attackers …

Sep 16, 2026
CVE-2026-92383
4.3 MEDIUM

A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserController::del/UserController::mod of the file apps/admin/controller/system/UserController.php of the component User …

Sep 16, 2026
CVE-2026-89031
5.4 MEDIUM

Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s_calendar_move_post AJAX handler in includes/Ajax/Post.php …

Sep 16, 2026
CVE-2026-88976
6.1 MEDIUM

Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.0-beta.1 builds, Plate core HTML deserialization APIs …

Sep 16, 2026
CVE-2026-84859
6.5 MEDIUM

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Blind SQL Injection The /api/events/search endpoint accepts a JSON body containing a sortBy array. The values …

Sep 16, 2026
CVE-2026-77401
6.8 MEDIUM

Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusted users to create and execute AccessControl-controlled Python …

Sep 16, 2026
CVE-2026-77119
5.9 MEDIUM

A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned …

Sep 16, 2026
CVE-2026-75029
5.3 MEDIUM

In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If …

Sep 16, 2026
CVE-2026-61709
5.3 MEDIUM

OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded …

Sep 16, 2026
CVE-2026-19668
5.3 MEDIUM

A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on …

Sep 16, 2026
CVE-2026-19033
6.5 MEDIUM

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message …

Sep 16, 2026
CVE-2025-36591
4.4 MEDIUM

Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability. A …

Sep 16, 2026
CVE-2026-92468
6.5 MEDIUM

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the …

Sep 16, 2026
CVE-2026-92365
4.3 MEDIUM

A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py. The manipulation results …

Sep 16, 2026
CVE-2026-92364
6.3 MEDIUM

A vulnerability has been found in itsourcecode Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /module/employee/index.php. The manipulation …

Sep 16, 2026
CVE-2026-92363
4.3 MEDIUM

A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_parser.cpp of the component JSON Parser. Executing a …

Sep 16, 2026
CVE-2026-92141
4.3 MEDIUM

Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

Sep 16, 2026
CVE-2026-92140
6.8 MEDIUM

Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in build causes, resulting in a stored cross-site …

Sep 16, 2026
CVE-2026-92139
6.5 MEDIUM

Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials …

Sep 16, 2026
CVE-2026-92138
4.2 MEDIUM

The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the submitted form rather than from the …

Sep 16, 2026
CVE-2026-92133
5.4 MEDIUM

Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the …

Sep 16, 2026
CVE-2026-92132
5.4 MEDIUM

Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity server …

Sep 16, 2026
CVE-2026-92131
4.2 MEDIUM

Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside …

Sep 16, 2026
CVE-2026-89030
4.3 MEDIUM

Adenion Blog2Social plugin for WordPress before 9.1.0 exposes the email addresses of all registered WordPress users to low-privileged accounts. The b2s_search_user AJAX handler in includes/Ajax/Get.php …

Sep 16, 2026
CVE-2026-89029
4.3 MEDIUM

Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to enumerate WordPress user accounts. The b2s_get_select_mandant_user AJAX handler in includes/Ajax/Get.php resolves arbitrary user IDs …

Sep 16, 2026
CVE-2026-78301
5.8 MEDIUM

A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a …

Sep 16, 2026
CVE-2026-56719
6.5 MEDIUM

MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the …

Sep 16, 2026
CVE-2026-19941
5.9 MEDIUM

An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same …

Sep 16, 2026
CVE-2026-19662
5.9 MEDIUM

An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a …

Sep 16, 2026
CVE-2026-92361
4.3 MEDIUM

A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdks/community/go/pkg/client/sse/client.go of the component SSE Client. Such …

Sep 16, 2026
CVE-2026-92360
6.3 MEDIUM

A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application …

Sep 16, 2026
CVE-2026-92463
6.5 MEDIUM

yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @PreAuthorize annotation is commented out, allowing authenticated back-office users without system:user:list …

Sep 16, 2026
CVE-2026-92462
6.5 MEDIUM

yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing any authenticated back-office user to delete arbitrary approval workflow steps. Attackers …

Sep 16, 2026
CVE-2026-92461
4.3 MEDIUM

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office user to access approval workflow data. Attackers …

Sep 16, 2026
CVE-2026-92460
6.5 MEDIUM

yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail. Attackers can …

Sep 16, 2026
CVE-2026-92459
6.5 MEDIUM

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission …

Sep 16, 2026
CVE-2026-92458
4.3 MEDIUM

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that allows authenticated back-office users to modify product sale status. Attackers can …

Sep 16, 2026
CVE-2026-92457
6.5 MEDIUM

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices. Attackers can call …

Sep 16, 2026
CVE-2026-92455
4.3 MEDIUM

yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office user to send SMS and email …

Sep 16, 2026
CVE-2026-92357
4.3 MEDIUM

A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impacted is an unknown function of the file model-processor.ts of the component Model Processor. The manipulation of …

Sep 16, 2026
CVE-2026-92356
4.3 MEDIUM

A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the file basic_functions.ts of the component Update Components. Executing a …

Sep 16, 2026
CVE-2026-86107
5.9 MEDIUM

The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments between authenticated overlay neighbors. This vulnerability impacts the VeloCloud VCMP …

Sep 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.