CVE Database

133011+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-18372

CSS injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated vault administrator to inject arbitrary CSS, affecting the web user interface displayed to other …

Aug 19, 2026
CVE-2026-18371

HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to affect web user interface contents displayed to other users.

Aug 19, 2026
CVE-2026-16440

In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deeply nested annotations causes a segmentation fault.

Aug 19, 2026
CVE-2026-76166
4.3 MEDIUM

A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single crafted UDP multicast datagram with a valid HTTP status line and a "Server:" …

Aug 19, 2026
CVE-2026-76164

AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission functionality. A low-privileged authenticated user with access to the crawler interface can …

Aug 19, 2026
CVE-2026-75900
6.1 MEDIUM

An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the buffer length against sizeof(bh), where bh is a pointer, instead …

Aug 19, 2026
CVE-2026-75589

Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. Each of the three compares the signature …

Aug 19, 2026
CVE-2026-72889

Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves the signature method class from the signature_method …

Aug 19, 2026
CVE-2026-58088
7.4 HIGH

The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the corresponding program headers, then iterated over the …

Aug 19, 2026
CVE-2026-58087
7.8 HIGH

The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dropped the lock protecting the set, allocated a buffer …

Aug 19, 2026
CVE-2026-58086

As an inadvertent side effect of an unrelated code change, PRIV_KTRACE was always denied to a jailed root user. Tracing configured by a jailed root …

Aug 19, 2026
CVE-2026-58085

After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to check whether the MAC verification step succeeded. The driver …

Aug 19, 2026
CVE-2026-58084

To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the current time for the timer's clock. For a timer using CLOCK_TAI this …

Aug 19, 2026
CVE-2026-58083
8.4 HIGH

While the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be enqueued on the kqueue's active list before …

Aug 19, 2026
CVE-2026-58082

The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate character output. Some ISO-2022 variants can require up to 10 …

Aug 19, 2026
CVE-2026-58081

Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output buffer before writing converted characters. An …

Aug 19, 2026
CVE-2026-49425

The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct. It did not first zero the stack struct. An unprivileged …

Aug 19, 2026
CVE-2026-49424

The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux siginfo_t. It did not first zero the stack struct. An unprivileged user …

Aug 19, 2026
CVE-2026-75981
7.2 HIGH

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting in versions up to and including …

Aug 19, 2026
CVE-2026-49423

When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cbc_decrypt() incremented the iovec index for every mbuf in the chain, including mbufs …

Aug 19, 2026
CVE-2026-15780
7.2 HIGH

The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' parameter in all versions …

Aug 19, 2026
CVE-2026-15446
6.4 MEDIUM

The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content in all versions up …

Aug 19, 2026
CVE-2026-18980
6.3 MEDIUM

A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the file src/tools/builtin/shell.rs. Such manipulation leads to command injection. …

Aug 6, 2026
CVE-2026-18976
6.3 MEDIUM

A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions of the file agent/agent_init.py of the component disabled_toolsets Handler. This …

Aug 6, 2026
CVE-2026-18974
5.3 MEDIUM

A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the file server.py of the component execute_tool_manually Endpoint. The …

Aug 6, 2026
CVE-2026-18973
7.3 HIGH

A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file server.py of the component …

Aug 6, 2026
CVE-2026-67873

A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment …

Aug 6, 2026
CVE-2026-67872

An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queue resize handling

Aug 6, 2026
CVE-2026-67871

Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddNodes, address_space_bs.c, sopc_node_mgt_helper_internal.c, and toolkit_test_server

Aug 6, 2026
CVE-2026-67870

In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with …

Aug 6, 2026
CVE-2026-67869
7.5 HIGH

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments …

Aug 6, 2026
CVE-2026-67531

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances to …

Aug 6, 2026
CVE-2026-52466

Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after …

Aug 6, 2026
CVE-2026-19028

H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size …

Aug 6, 2026
CVE-2026-19027

The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_atomic functions in H5Znbit.c in HDF5 through 2.3.0 advance a read index into the compressed chunk buffer without bounding it against …

Aug 6, 2026
CVE-2026-18970
7.3 HIGH

A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected element is an unknown function of the …

Aug 6, 2026
CVE-2026-18969
7.3 HIGH

A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the file /dm/dispatch/userinfo/upload. Performing …

Aug 6, 2026
CVE-2026-18968
4.3 MEDIUM

A security vulnerability has been detected in ttttonyhe OBlog up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f. This issue affects some unknown processing of the file /tags.php. Such manipulation of …

Aug 6, 2026
CVE-2023-54389

Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

Aug 6, 2026
CVE-2023-54388

Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

Aug 6, 2026
CVE-2023-54387

Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

Aug 6, 2026
CVE-2023-54386

Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

Aug 6, 2026
CVE-2023-54385

Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

Aug 6, 2026
CVE-2023-54384

Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

Aug 6, 2026
CVE-2023-54383

Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

Aug 6, 2026
CVE-2023-54382

Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

Aug 6, 2026
CVE-2023-54381

Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

Aug 6, 2026
CVE-2023-54380

Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

Aug 6, 2026
CVE-2023-54379

Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

Aug 6, 2026
CVE-2023-54378

Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

Aug 6, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.