CVE Database

133011+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-63456
9.8 CRITICAL

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access …

Aug 4, 2026
CVE-2026-63455
9.8 CRITICAL

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access …

Aug 4, 2026
CVE-2026-58075

A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.

Aug 4, 2026
CVE-2026-58074

A vulnerability allowing a high-privileged user to execute arbitrary code on the server.

Aug 4, 2026
CVE-2026-58073

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.

Aug 4, 2026
CVE-2026-58072

A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution.

Aug 4, 2026
CVE-2026-58071

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an …

Aug 4, 2026
CVE-2026-58067

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.

Aug 4, 2026
CVE-2026-56848
7.5 HIGH

A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, …

Aug 4, 2026
CVE-2026-48121
6.7 MEDIUM

@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and below are vulnerable to NoSQL injection: checkpoint identifiers (thread_id, checkpoint_ns, checkpoint_id) …

Aug 4, 2026
CVE-2026-18787
8.8 HIGH

A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the component RPC …

Aug 4, 2026
CVE-2026-18785
5.3 MEDIUM

A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a manipulation can lead to use after …

Aug 4, 2026
CVE-2026-18784
5.3 MEDIUM

A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute of the file src/client/ua_client_highlevel.c. Performing a manipulation results in …

Aug 4, 2026
CVE-2026-18775
6.3 MEDIUM

A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/browser_tool.py of the component Browser …

Aug 4, 2026
CVE-2026-18774
6.3 MEDIUM

A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the component xAI Image …

Aug 4, 2026
CVE-2026-15920
6.1 MEDIUM

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating …

Aug 4, 2026
CVE-2026-15830
5.3 MEDIUM

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested …

Aug 4, 2026
CVE-2026-15337
5.3 MEDIUM

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, …

Aug 4, 2026
CVE-2026-15314

Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation …

Aug 4, 2026
CVE-2026-15307
8.8 HIGH

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by …

Aug 4, 2026
CVE-2025-29296
9.8 CRITICAL

H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C …

Aug 4, 2026
CVE-2026-69254

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-provided nodeVMOptions and merged …

Aug 4, 2026
CVE-2026-69253

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and …

Aug 4, 2026
CVE-2026-69252

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only …

Aug 4, 2026
CVE-2026-69110
9.1 CRITICAL

OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by …

Aug 4, 2026
CVE-2026-69100
8.8 HIGH

LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database …

Aug 4, 2026
CVE-2026-69098
9.8 CRITICAL

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON …

Aug 4, 2026
CVE-2026-25292
7.6 HIGH

Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.

Aug 4, 2026
CVE-2026-25289
9.6 CRITICAL

Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.

Aug 4, 2026
CVE-2026-25288
7.4 HIGH

Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.

Aug 4, 2026
CVE-2026-24084
7.5 HIGH

Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.

Aug 4, 2026
CVE-2026-24083
7.8 HIGH

Memory Corruption while processing IOCTL device driver requests with invalid arguments.

Aug 4, 2026
CVE-2026-24080
7.8 HIGH

Memory Corruption when handling malformed request parameters in the fingerprint TA.

Aug 4, 2026
CVE-2026-24079
8.1 HIGH

Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.

Aug 4, 2026
CVE-2026-24078
6.5 MEDIUM

Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.

Aug 4, 2026
CVE-2026-24077
6.5 MEDIUM

Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.

Aug 4, 2026
CVE-2026-24076
6.7 MEDIUM

Memory Corruption when processing registry values with incorrect types using a direct query method.

Aug 4, 2026
CVE-2026-21366
7.8 HIGH

Memory corruption while processing a packet with a size close to the maximum allowed value.

Aug 4, 2026
CVE-2026-18801

OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution values. An attacker who can create or update a customer …

Aug 4, 2026
CVE-2026-18773
6.3 MEDIUM

A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component …

Aug 4, 2026
CVE-2026-10032

The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript: URI …

Aug 4, 2026
CVE-2026-69251

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory …

Aug 4, 2026
CVE-2026-69250

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST …

Aug 4, 2026
CVE-2026-68494

The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the …

Aug 4, 2026
CVE-2026-67618
6.5 MEDIUM

marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operator API keys by embedding a malicious base_url in PEP-723 inline …

Aug 4, 2026
CVE-2026-67200
7.5 HIGH

Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files from the server filesystem by including literal ../ segments …

Aug 4, 2026
CVE-2026-67199
6.5 MEDIUM

Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a crafted expression containing …

Aug 4, 2026
CVE-2026-67198
7.5 HIGH

Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to crash the server process by sending malformed or …

Aug 4, 2026
CVE-2026-67196
5.4 MEDIUM

Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to inject arbitrary HTML and JavaScript by writing table cell …

Aug 4, 2026
CVE-2026-67195
8.8 HIGH

Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the …

Aug 4, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.