CVE Database

45744+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-6580
7.3 HIGH

A security vulnerability has been detected in liangliangyy DjangoBlog up to 2.1.0.0. Affected is an unknown function of the file owntracks/views.py of the component Amap …

Apr 19, 2026
CVE-2026-6577
7.3 HIGH

A vulnerability was identified in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file owntracks/views.py of the component logtracks …

Apr 19, 2026
CVE-2026-6574
7.3 HIGH

A vulnerability has been found in osuuu LightPicture up to 1.2.2. This issue affects some unknown processing of the file /public/install/lp.sql of the component API …

Apr 19, 2026
CVE-2026-6569
7.3 HIGH

A vulnerability was identified in kodcloud KodExplorer up to 4.52. This impacts the function fileGet of the file /app/controller/share.class.php of the component fileGet Endpoint. Such …

Apr 19, 2026
CVE-2026-6568
7.3 HIGH

A vulnerability was determined in kodcloud KodExplorer up to 4.52. This affects the function share.class.php::initShareOld of the file /app/controller/share.class.php of the component Public Share Handler. …

Apr 19, 2026
CVE-2026-6563
8.8 HIGH

A vulnerability has been found in H3C Magic B1 up to 100R004. The affected element is the function SetAPWifiorLedInfoById of the file /goform/aspForm. The manipulation …

Apr 19, 2026
CVE-2026-6562
7.3 HIGH

A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is the function getListByPage of the file /index/Search/index.html. Executing a manipulation of the argument keyword …

Apr 19, 2026
CVE-2026-6560
8.8 HIGH

A security vulnerability has been detected in H3C Magic B0 up to 100R002. This vulnerability affects the function Edit_BasicSSID of the file /goform/aspForm. Such manipulation …

Apr 19, 2026
CVE-2026-32228
7.5 HIGH

UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 …

Apr 18, 2026
CVE-2026-30912
7.5 HIGH

In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing …

Apr 18, 2026
CVE-2026-30898
8.8 HIGH

An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be used …

Apr 18, 2026
CVE-2026-25917
7.2 HIGH

Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary …

Apr 18, 2026
CVE-2026-6518
8.8 HIGH

The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all …

Apr 18, 2026
CVE-2026-40487
8.9 HIGH

Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, …

Apr 18, 2026
CVE-2026-35582
8.8 HIGH

Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable to OS command injection because it interpolates temporary file …

Apr 18, 2026
CVE-2026-40350
8.8 HIGH

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can access …

Apr 18, 2026
CVE-2026-35465
7.5 HIGH

SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, …

Apr 18, 2026
CVE-2026-40581
8.1 HIGH

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs permanent, irreversible deletion of family records …

Apr 18, 2026
CVE-2026-40349
8.8 HIGH

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate …

Apr 18, 2026
CVE-2026-40348
7.7 HIGH

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can trigger …

Apr 18, 2026
CVE-2026-40323
7.5 HIGH

SP1 is a zero‑knowledge virtual machine that proves the correct execution of programs compiled for the RISC-V architecture. In versions 6.0.0 through 6.0.2, a soundness …

Apr 18, 2026
CVE-2026-2262
7.5 HIGH

The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.21 via the `/wp-json/wp/v2/eablocks/ea_appointments/` REST API …

Apr 18, 2026
CVE-2026-40481
7.5 HIGH

monetr is a budgeting application for recurring expenses. In versions 1.12.3 and below, the public Stripe webhook endpoint buffers the entire request body into memory …

Apr 17, 2026
CVE-2026-40474
7.6 HIGH

wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares permission_required = 'config.change_gymconfig' but inherits WgerFormMixin instead of …

Apr 17, 2026
CVE-2026-40352
8.8 HIGH

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An authenticated attacker can …

Apr 17, 2026
CVE-2026-40321
8.0 HIGH

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially …

Apr 17, 2026
CVE-2026-40527
7.8 HIGH

radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences …

Apr 17, 2026
CVE-2026-40303
7.5 HIGH

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.GetSessionCookie parses an attacker-supplied cookie chunk count and calls make([]string, …

Apr 17, 2026
CVE-2026-40286
7.5 HIGH

WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the 'Member Registration' …

Apr 17, 2026
CVE-2026-40285
8.8 HIGH

WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection vulnerability in dao/memorando/UsuarioDAO.php. The cpf_usuario POST parameter overwrites the …

Apr 17, 2026
CVE-2026-40196
8.1 HIGH

HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user …

Apr 17, 2026
CVE-2026-35603
7.3 HIGH

Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide default configuration from C:\ProgramData\ClaudeCode\managed-settings.json without validating …

Apr 17, 2026
CVE-2026-35512
8.8 HIGH

xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implementation due to …

Apr 17, 2026
CVE-2026-40461
7.5 HIGH

Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug settings (e.g., enabling SSH), allowing unauthorized state changes that can facilitate …

Apr 17, 2026
CVE-2026-40434
8.1 HIGH

Anviz CrossChex Standard lacks source verification in the client/server channel, enabling TCP packet injection by an attacker on the same network to alter or disrupt …

Apr 17, 2026
CVE-2026-40066
8.8 HIGH

Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and executes a script resulting in unauthenticated …

Apr 17, 2026
CVE-2026-35682
8.8 HIGH

Anviz CX2 Lite is vulnerable to an authenticated command injection via a filename parameter that enables arbitrary command execution (e.g., starting telnetd), resulting in root‑level …

Apr 17, 2026
CVE-2026-35215
7.5 HIGH

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the sdl_desc() function does not validate the length of …

Apr 17, 2026
CVE-2026-34232
7.5 HIGH

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_status_vector() function does not handle the isc_arg_cstring type …

Apr 17, 2026
CVE-2026-32650
7.5 HIGH

Anviz CrossChex Standard is vulnerable when an attacker manipulates the TDS7 PreLogin to disable encryption, causing database credentials to be sent in plaintext and enabling …

Apr 17, 2026
CVE-2026-32623
8.1 HIGH

xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in the NeutrinoRDP module. When proxying RDP sessions from …

Apr 17, 2026
CVE-2026-32324
7.7 HIGH

Anviz CX7 Firmware is vulnerable because the application embeds reusable certificate/key material, enabling decryption of MQTT traffic and potential interaction with device messaging channels at …

Apr 17, 2026
CVE-2026-32107
8.8 HIGH

xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle an error during the privilege drop …

Apr 17, 2026
CVE-2026-32105
7.7 HIGH

xrdp is an open source RDP server. In versions through 0.10.5, xrdp does not implement verification for the Message Authentication Code (MAC) signature of encrypted …

Apr 17, 2026
CVE-2026-33337
7.5 HIGH

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when deserializing a slice packet, the xdr_datum() function does …

Apr 17, 2026
CVE-2026-28224
8.2 HIGH

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the server receives an op_crypt_key_callback packet without prior …

Apr 17, 2026
CVE-2026-28212
7.5 HIGH

Firebird is an open-source relational database management system. In versions prior to 6.0.0, 5.0.4, 4.0.7 and 3.0.14, when processing an op_slice network packet, the server …

Apr 17, 2026
CVE-2026-27890
8.2 HIGH

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when processing CNCT_specific_data segments during authentication, the server assumes …

Apr 17, 2026
CVE-2026-5718
8.1 HIGH

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and …

Apr 17, 2026
CVE-2026-5710
7.5 HIGH

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in …

Apr 17, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.