CVE Database

133011+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-66315
7.5 HIGH

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Aug 4, 2026
CVE-2026-66314
6.5 MEDIUM

Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Aug 4, 2026
CVE-2026-66313
6.8 MEDIUM

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

Aug 4, 2026
CVE-2026-66312
6.5 MEDIUM

Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

Aug 4, 2026
CVE-2026-66311
6.2 MEDIUM

Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

Aug 4, 2026
CVE-2026-66310
7.7 HIGH

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

Aug 4, 2026
CVE-2026-65804
6.1 MEDIUM

Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Aug 4, 2026
CVE-2026-65802
7.4 HIGH

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

Aug 4, 2026
CVE-2026-62870
8.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

Aug 4, 2026
CVE-2026-18686
9.8 CRITICAL

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web …

Aug 4, 2026
CVE-2026-18685
9.8 CRITICAL

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. …

Aug 4, 2026
CVE-2026-11836

Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in subsystem mode allows an attacker with access to the integrator's debug …

Aug 4, 2026
CVE-2026-11835

Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow::run()) in subsystem mode allows a compromised local attacker to silently bypass …

Aug 4, 2026
CVE-2026-67978
7.5 HIGH

An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN …

Aug 3, 2026
CVE-2026-67673
4.6 MEDIUM

A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is triggered when processing the edl fw_flash command, where …

Aug 3, 2026
CVE-2026-48399
7.5 HIGH

Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could …

Aug 3, 2026
CVE-2026-48333
9.8 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain …

Aug 3, 2026
CVE-2026-48331
10.0 CRITICAL

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not …

Aug 3, 2026
CVE-2026-48330
10.0 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in …

Aug 3, 2026
CVE-2026-48326
9.9 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in …

Aug 3, 2026
CVE-2026-48323
10.0 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code …

Aug 3, 2026
CVE-2026-48317
9.6 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code …

Aug 3, 2026
CVE-2026-18684
9.8 CRITICAL

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. …

Aug 3, 2026
CVE-2026-18667
9.6 CRITICAL

A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to …

Aug 3, 2026
CVE-2026-69249

python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, when resolving invalid certificate chains that include duplicate …

Aug 3, 2026
CVE-2026-69248

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrained CA permits the DNS …

Aug 3, 2026
CVE-2026-69247

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome …

Aug 3, 2026
CVE-2026-67977
7.5 HIGH

An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Aug 3, 2026
CVE-2026-67975

Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands.

Aug 3, 2026
CVE-2026-67974

A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial …

Aug 3, 2026
CVE-2026-67973
7.5 HIGH

An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.

Aug 3, 2026
CVE-2026-67970

Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.

Aug 3, 2026
CVE-2026-67969

An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry.

Aug 3, 2026
CVE-2026-67617
4.8 MEDIUM

Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting …

Aug 3, 2026
CVE-2026-67616
4.3 MEDIUM

Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create …

Aug 3, 2026
CVE-2026-48115

Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a vulnerability in …

Aug 3, 2026
CVE-2026-47746

Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, are vulnerable to timing attacks during JSON-LD signature …

Aug 3, 2026
CVE-2026-46714

Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to 2026.5.4, contain a vulnerability that can cause the Misskey …

Aug 3, 2026
CVE-2026-46713

Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation …

Aug 3, 2026
CVE-2026-46712

Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior to 2026.5.4, contain a vulnerability where a lack of proper …

Aug 3, 2026
CVE-2026-18682
3.1 LOW

A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /api/upload of the component File Upload …

Aug 3, 2026
CVE-2026-10849
8.2 HIGH

The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). …

Aug 3, 2026
CVE-2026-69246
7.2 HIGH

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host …

Aug 3, 2026
CVE-2026-69245
6.5 MEDIUM

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes …

Aug 3, 2026
CVE-2026-69244

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser …

Aug 3, 2026
CVE-2026-69243

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating …

Aug 3, 2026
CVE-2026-69240
9.8 CRITICAL

Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function …

Aug 3, 2026
CVE-2026-67976
7.5 HIGH

The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Denial of Service (DoS) via …

Aug 3, 2026
CVE-2026-67972

An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data is stored, possibly leading to an …

Aug 3, 2026
CVE-2026-66065

Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have …

Aug 3, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.