CVE Database

11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-12946
9.9 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user …

Jul 30, 2026
CVE-2026-18245
9.0 CRITICAL

Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, …

Jul 30, 2026
CVE-2026-15976
9.8 CRITICAL

SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickle …

Jul 30, 2026
CVE-2026-15971
9.8 CRITICAL

SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, enabling code execution on …

Jul 30, 2026
CVE-2026-15969
9.8 CRITICAL

SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads.

Jul 30, 2026
CVE-2026-13435
9.9 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.

Jul 30, 2026
CVE-2026-12943
9.8 CRITICAL

IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user …

Jul 30, 2026
CVE-2026-12118
9.8 CRITICAL

IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of …

Jul 30, 2026
CVE-2026-13379
9.1 CRITICAL

The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted …

Jul 30, 2026
CVE-2026-12940
9.8 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. …

Jul 30, 2026
CVE-2026-52680
9.8 CRITICAL

Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the …

Jul 30, 2026
CVE-2026-4978
9.8 CRITICAL

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL Injection. This issue affects …

Jul 30, 2026
CVE-2026-28812
9.8 CRITICAL

UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to …

Jul 30, 2026
CVE-2026-28323
9.8 CRITICAL

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.

Jul 30, 2026
CVE-2026-15435
9.8 CRITICAL

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could …

Jul 30, 2026
CVE-2026-11707
9.3 CRITICAL

IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.

Jul 30, 2026
CVE-2026-59310
9.8 CRITICAL KEV

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute …

Jul 30, 2026
CVE-2026-59309
9.8 CRITICAL

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to …

Jul 30, 2026
CVE-2026-54363
9.1 CRITICAL

CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used …

Jul 30, 2026
CVE-2026-47876
9.3 CRITICAL

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with …

Jul 30, 2026
CVE-2026-17544
9.8 CRITICAL

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* …

Jul 30, 2026
CVE-2026-17543
9.8 CRITICAL

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from …

Jul 30, 2026
CVE-2026-7849
9.8 CRITICAL

Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed …

Jul 30, 2026
CVE-2026-44108
9.8 CRITICAL

Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window …

Jul 30, 2026
CVE-2026-44104
9.8 CRITICAL

The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote …

Jul 30, 2026
CVE-2026-44101
9.8 CRITICAL

Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and …

Jul 30, 2026
CVE-2026-44100
9.4 CRITICAL

The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files …

Jul 30, 2026
CVE-2026-44092
9.1 CRITICAL

An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may …

Jul 30, 2026
CVE-2026-44091
9.1 CRITICAL

An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system …

Jul 30, 2026
CVE-2026-44090
9.8 CRITICAL

Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may …

Jul 30, 2026
CVE-2026-58066
9.8 CRITICAL

Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature …

Jul 30, 2026
CVE-2026-58046
9.9 CRITICAL

Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, …

Jul 30, 2026
CVE-2026-14602
9.0 CRITICAL

The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary PHP objects, which …

Jul 30, 2026
CVE-2026-16610
9.8 CRITICAL

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via …

Jul 30, 2026
CVE-2026-48449
10.0 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. …

Jul 30, 2026
CVE-2026-18015
9.6 CRITICAL

Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted …

Jul 30, 2026
CVE-2026-18002
9.6 CRITICAL

Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to …

Jul 30, 2026
CVE-2026-17991
9.6 CRITICAL

Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially …

Jul 30, 2026
CVE-2026-17990
9.6 CRITICAL

Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially …

Jul 30, 2026
CVE-2026-17987
9.6 CRITICAL

Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially …

Jul 30, 2026
CVE-2026-17947
9.6 CRITICAL

Use after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Jul 30, 2026
CVE-2026-17940
9.6 CRITICAL

Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process …

Jul 30, 2026
CVE-2026-17924
9.6 CRITICAL

Use after free in DNS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jul 30, 2026
CVE-2026-17865
9.6 CRITICAL

Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform …

Jul 30, 2026
CVE-2026-17856
9.6 CRITICAL

Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform …

Jul 30, 2026
CVE-2026-17855
9.6 CRITICAL

Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jul 30, 2026
CVE-2026-17848
9.6 CRITICAL

Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. …

Jul 30, 2026
CVE-2026-17847
9.6 CRITICAL

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a …

Jul 30, 2026
CVE-2026-17837
9.6 CRITICAL

Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially …

Jul 30, 2026
CVE-2026-17834
9.6 CRITICAL

Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially …

Jul 30, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.