CVE Database

45744+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-40912
8.2 HIGH

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in …

Apr 30, 2026
CVE-2026-33451
7.8 HIGH

CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can send …

Apr 30, 2026
CVE-2026-33449
7.5 HIGH

CVE-2026-33449 is a buffer overflow in a message handling function of the Secure Access client prior to 14.50. Attackers with control of a modified server …

Apr 30, 2026
CVE-2025-56568
7.5 HIGH

Assertion failure vulnerability in the PCO (Protocol Configuration Options) parser in the SMF (Session Management Function) component of Open5GS before v2.7.5 allows remote attackers to …

Apr 30, 2026
CVE-2025-46115
7.5 HIGH

An issue in open5gs v.2.7.3 allows a remote attacker to cause a denial of service via a crafted PDU Session Modification Request

Apr 30, 2026
CVE-2026-7461
7.2 HIGH

Improper neutralization of inputs used in an OS command in the FSx Windows File Server volume mounting component in Amazon ECS Agent on Windows before …

Apr 30, 2026
CVE-2026-40904
8.1 HIGH

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew …

Apr 30, 2026
CVE-2026-40601
7.5 HIGH

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew …

Apr 30, 2026
CVE-2026-40600
8.1 HIGH

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew …

Apr 30, 2026
CVE-2026-40595
7.5 HIGH

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew …

Apr 30, 2026
CVE-2026-36765
8.8 HIGH

An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated attackers to execute arbitrary code via injecting a crafted payload.

Apr 30, 2026
CVE-2026-36762
8.8 HIGH

An issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal …

Apr 30, 2026
CVE-2026-33845
7.5 HIGH

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting …

Apr 30, 2026
CVE-2025-51846
7.5 HIGH

CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users of a CryptPad instance. Fixed …

Apr 30, 2026
CVE-2022-50992
7.5 HIGH

Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpoint that allows unauthenticated …

Apr 30, 2026
CVE-2026-5174
7.7 HIGH

Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, …

Apr 30, 2026
CVE-2026-36960
8.8 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.0.0. The device does not implement CSRF protection …

Apr 30, 2026
CVE-2026-36340
8.1 HIGH

An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function

Apr 30, 2026
CVE-2026-36959
7.5 HIGH

U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. This allows an attacker on the local network …

Apr 30, 2026
CVE-2026-36958
7.5 HIGH

A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concurrent HTTP requests to random or non-existent endpoints …

Apr 30, 2026
CVE-2026-36957
7.5 HIGH

Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI handler. By initiating …

Apr 30, 2026
CVE-2026-36956
8.8 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireless router V1.0.0. The router fails to …

Apr 30, 2026
CVE-2026-7246
7.2 HIGH

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged …

Apr 30, 2026
CVE-2026-2892
7.5 HIGH

The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including, 3.1.4. This is due to the …

Apr 30, 2026
CVE-2026-7402
8.1 HIGH

Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

Apr 30, 2026
CVE-2026-7399
8.1 HIGH

Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege Abuse. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

Apr 30, 2026
CVE-2025-14576
7.8 HIGH

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt …

Apr 30, 2026
CVE-2024-13971
7.5 HIGH

Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read access to …

Apr 30, 2026
CVE-2026-41882
7.4 HIGH

In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server

Apr 30, 2026
CVE-2026-31693
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In several places in the code, we have a …

Apr 30, 2026
CVE-2026-31787
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: fix double free via VMA splitting privcmd_vm_ops defines .close (privcmd_close), but neither .may_split nor …

Apr 30, 2026
CVE-2026-31786
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Buffer overflow in drivers/xen/sys-hypervisor.c The build id returned by HYPERVISOR_xen_version(XENVER_build_id) is neither NUL terminated nor …

Apr 30, 2026
CVE-2026-42800
7.4 HIGH

NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation. This vulnerability is associated with program files sip/utils/src/sipuri.c.

Apr 30, 2026
CVE-2026-42799
7.4 HIGH

Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects Kestrel: before 2026/02/10.

Apr 30, 2026
CVE-2026-42512
8.1 HIGH

As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. The code which expands the …

Apr 30, 2026
CVE-2026-39457
7.8 HIGH

When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whether the provided socket descriptor …

Apr 30, 2026
CVE-2026-35547
8.1 HIGH

When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of validation allows a malicious program to …

Apr 30, 2026
CVE-2026-22070
7.1 HIGH

ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.

Apr 30, 2026
CVE-2026-7164
7.5 HIGH

Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a stack overflow and panic. Remote attackers can craft packets …

Apr 30, 2026
CVE-2026-7270
7.8 HIGH

An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2) argument buffers. The …

Apr 30, 2026
CVE-2026-5402
8.8 HIGH

TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution

Apr 30, 2026
CVE-2026-42511
8.1 HIGH

The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is …

Apr 30, 2026
CVE-2024-39847
7.5 HIGH

Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access …

Apr 30, 2026
CVE-2025-13030
7.1 HIGH

All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint. An attacker can upload malicious files …

Apr 30, 2026
CVE-2026-7470
8.8 HIGH

A flaw has been found in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. Affected is the function sub_427C3C of the file /goform/SafeMacFilter. This manipulation of the argument page causes …

Apr 30, 2026
CVE-2026-7468
7.3 HIGH

A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the file /smart-admin-api/druid/index.html of the component Demo …

Apr 30, 2026
CVE-2026-7446
7.3 HIGH

A vulnerability was detected in VetCoders mcp-server-semgrep 1.0.0. This affects the function analyze_results/filter_results/export_results/compare_results/scan_directory/create_rule of the file src/index.ts of the component MCP Interface. The manipulation of …

Apr 30, 2026
CVE-2026-7443
7.3 HIGH

A weakness has been identified in BurtTheCoder mcp-dnstwist up to 1.0.4. Affected by this vulnerability is the function fuzz_domain of the file src/index.ts of the …

Apr 29, 2026
CVE-2026-7420
8.8 HIGH

A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file route/goform/ConfigAdvideo. The manipulation of …

Apr 29, 2026
CVE-2026-7419
8.8 HIGH

A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the function strcpy of the file route/goform/formTaskEdit_ap. The manipulation of the …

Apr 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.