CVE Database

45744+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-40320
7.8 HIGH

Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the ConformityCheck class rendered the rule parameter through Jinja2's default Template() …

Apr 17, 2026
CVE-2025-65104
7.9 HIGH

Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQLDA fields when communicating …

Apr 17, 2026
CVE-2026-40518
7.1 HIGH

ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation where the agent name validation is bypassed. …

Apr 17, 2026
CVE-2026-40516
8.3 HIGH

OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the web_fetch and web_search tools that allows attackers to access private and localhost HTTP …

Apr 17, 2026
CVE-2026-40515
7.5 HIGH

OpenHarness before commit bd4df81 contains a permission bypass vulnerability that allows attackers to read sensitive files by exploiting incomplete path normalization in the permission checker. …

Apr 17, 2026
CVE-2026-3464
8.8 HIGH

The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in the 'ajax_attach_file' function …

Apr 17, 2026
CVE-2026-21733
7.3 HIGH

Vulnerability in Imagination Technologies Graphics DDK on Linux, Android -- RESERVED

Apr 17, 2026
CVE-2026-6490
7.3 HIGH

A weakness has been identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. Impacted is an unknown function of the file admin/deletecourse.php of the component GET Request …

Apr 17, 2026
CVE-2026-40459
8.8 HIGH

PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters, potentially resulting in …

Apr 17, 2026
CVE-2026-31317
7.5 HIGH

Craftql v1.3.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the vendor/markhuot/craftql/src/Listeners/GetAssetsFieldSchema.php file

Apr 17, 2026
CVE-2026-6507
7.5 HIGH

A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet …

Apr 17, 2026
CVE-2026-6483
7.2 HIGH

A vulnerability was found in Wavlink WL-WN530H4 20220721. This vulnerability affects the function strcat/snprintf of the file /cgi-bin/internet.cgi. The manipulation results in os command injection. …

Apr 17, 2026
CVE-2026-23776
7.2 HIGH

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 …

Apr 17, 2026
CVE-2026-23778
7.2 HIGH

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 …

Apr 17, 2026
CVE-2026-23775
7.6 HIGH

Dell PowerProtect Data Domain appliances with Data Domain Operating System (DD OS) of Feature Release versions 8.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.10 …

Apr 17, 2026
CVE-2025-36568
7.8 HIGH

Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through …

Apr 17, 2026
CVE-2026-33392
7.2 HIGH

In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass

Apr 17, 2026
CVE-2026-23853
8.4 HIGH

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 …

Apr 17, 2026
CVE-2026-4659
7.5 HIGH

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV URL parameter in versions up to, and …

Apr 17, 2026
CVE-2026-6482
7.8 HIGH

The Rapid7 Insight Agent (versions > 4.1.0.2) is vulnerable to a local privilege escalation attack that allows users to gain SYSTEM level control of a …

Apr 17, 2026
CVE-2026-6421
7.0 HIGH

A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library msimg32.dll. The manipulation leads …

Apr 17, 2026
CVE-2026-21719
7.2 HIGH

An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to execute an arbitrary OS …

Apr 17, 2026
CVE-2026-5807
7.5 HIGH

Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel root token generation or rekey operations, occupying the single …

Apr 17, 2026
CVE-2026-4525
7.5 HIGH

If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded …

Apr 17, 2026
CVE-2026-3605
8.1 HIGH

An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized …

Apr 17, 2026
CVE-2026-5231
7.2 HIGH

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in all versions up to, and including, 14.16.4. This …

Apr 17, 2026
CVE-2026-40262
8.7 HIGH

Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset delivery handler serves uploaded files inline and relies on magic-byte detection …

Apr 17, 2026
CVE-2026-22734
8.6 HIGH

Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UAA-protected systems. …

Apr 17, 2026
CVE-2026-40318
8.5 HIGH

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id parameter …

Apr 16, 2026
CVE-2026-40259
8.1 HIGH

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, the /api/av/removeUnusedAttributeView endpoint is protected only by generic authentication that accepts publish-service …

Apr 16, 2026
CVE-2026-41113
8.1 HIGH

sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remote.c.

Apr 16, 2026
CVE-2026-40248
7.5 HIGH

free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the handler for creating or updating …

Apr 16, 2026
CVE-2026-40247
7.5 HIGH

free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the handler for reading Traffic Influence …

Apr 16, 2026
CVE-2026-40246
7.5 HIGH

free5GC is an open-source implementation of the 5G core network. In versions 1.4.2 and below of the UDR service, the handler for deleting Traffic Influence …

Apr 16, 2026
CVE-2026-40170
7.5 HIGH

ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack …

Apr 16, 2026
CVE-2026-40901
8.8 HIGH

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below ship the legacy velocity-1.7.jar, which pulls in commons-collections-3.2.1.jar containing the InvokerTransformer deserialization …

Apr 16, 2026
CVE-2026-40900
8.8 HIGH

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /de2api/datasetData/previewSql endpoint. The user-supplied SQL …

Apr 16, 2026
CVE-2026-33207
8.8 HIGH

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /datasource/getTableField endpoint. The getTableFiledSql method …

Apr 16, 2026
CVE-2026-6442
8.3 HIGH

Improper validation of bash commands in Snowflake Cortex Code CLI versions prior to 1.0.25 allowed subsequent commands to execute outside the sandbox. An attacker could …

Apr 16, 2026
CVE-2026-33121
8.8 HIGH

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API datasource saving process. The …

Apr 16, 2026
CVE-2026-33084
8.8 HIGH

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the sort parameter of the /de2api/datasetData/enumValueObj …

Apr 16, 2026
CVE-2026-41082
7.3 HIGH

In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.

Apr 16, 2026
CVE-2026-33083
8.8 HIGH

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the orderDirection parameter used in dataset-related …

Apr 16, 2026
CVE-2026-5426
7.5 HIGH

Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code …

Apr 16, 2026
CVE-2026-3324
8.2 HIGH

Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration.

Apr 16, 2026
CVE-2026-37344
7.2 HIGH

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_location.php.

Apr 16, 2026
CVE-2026-37343
7.2 HIGH

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_user.php.

Apr 16, 2026
CVE-2026-37342
7.2 HIGH

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_parked_details.php.

Apr 16, 2026
CVE-2026-37341
7.2 HIGH

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_category.php.

Apr 16, 2026
CVE-2026-37337
7.3 HIGH

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_playlist.php.

Apr 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.