CVE Database

57293+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-71388
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Sep 8, 2026
CVE-2026-71357
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Sep 8, 2026
CVE-2026-71356
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Sep 8, 2026
CVE-2026-52486
6.6 MEDIUM

An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument module

Sep 8, 2026
CVE-2026-49883
5.5 MEDIUM

In checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due to a missing permission check. This could lead to …

Sep 8, 2026
CVE-2026-27227
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2026-19872
6.1 MEDIUM

HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message. The wrappers and renderers that emit …

Sep 8, 2026
CVE-2026-19713
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Sep 8, 2026
CVE-2026-19644
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Sep 8, 2026
CVE-2026-19612
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Sep 8, 2026
CVE-2026-19479
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Sep 8, 2026
CVE-2025-64868
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2025-64866
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2025-64854
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2025-64838
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2025-64830
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2025-64618
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2025-64610
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2025-64589
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2025-64588
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2025-64584
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2025-64542
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Sep 8, 2026
CVE-2026-86804
5.3 MEDIUM

A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.10. This vulnerability affects the function CPAResource of the file apps/manager-server/internal/http/controller/proxy/handler.go of the component HTTP Handler. …

Sep 8, 2026
CVE-2026-86675
6.3 MEDIUM

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/us_edit.php. Such manipulation of the argument …

Sep 8, 2026
CVE-2026-86674
6.3 MEDIUM

A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this vulnerability is the function session_start of the file login.php. The …

Sep 8, 2026
CVE-2026-69642
6.5 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.

Sep 8, 2026
CVE-2026-66308
6.5 MEDIUM

Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-66306
6.5 MEDIUM

Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-66303
6.5 MEDIUM

Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-63523
6.5 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.

Sep 8, 2026
CVE-2026-55256
6.5 MEDIUM

In parsePartHeaders of multiple files, there is a possible persistent denial of service due to improper input validation. This could lead to remote denial of …

Sep 8, 2026
CVE-2026-45527
4.3 MEDIUM

In convertCleanApertureToRect of HeifCleanAperture.cpp, there is a possible way to cause a temporary denial of service due to an integer overflow. This could lead to …

Sep 8, 2026
CVE-2026-28633
5.5 MEDIUM

In initForUserNoTracing of VoiceInteractionManagerService.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with …

Sep 8, 2026
CVE-2026-28627
4.3 MEDIUM

In btm_sec_encrypt_change of btm_sec.cc, there is a possible downgrade attack due to a logic error in the code. This could lead to remote information disclosure …

Sep 8, 2026
CVE-2026-28617
5.5 MEDIUM

In add of WifiNetworkSuggestionsManager.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denial of service with no additional …

Sep 8, 2026
CVE-2026-28596
5.5 MEDIUM

In parseInterventionFromXml of GameManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with …

Sep 8, 2026
CVE-2026-28584
5.5 MEDIUM

In createSessionInternal of PackageInstallerService.java, there is a possible way to permanently DoS the device due to a logic error in the code. This could lead …

Sep 8, 2026
CVE-2026-9215
6.7 MEDIUM

A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator …

Sep 8, 2026
CVE-2026-86672
5.3 MEDIUM

A vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function of the file example.7z of the component …

Sep 8, 2026
CVE-2026-85875
5.5 MEDIUM

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-83991
5.5 MEDIUM

Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.

Sep 8, 2026
CVE-2026-83951
5.5 MEDIUM

Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-83949
5.5 MEDIUM

Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-83501
5.5 MEDIUM

Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-81958
5.5 MEDIUM

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-81824
4.7 MEDIUM

The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered …

Sep 8, 2026
CVE-2026-81823
5.3 MEDIUM

The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure. Write operations are …

Sep 8, 2026
CVE-2026-81401
5.5 MEDIUM

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-81400
5.5 MEDIUM

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-81399
5.5 MEDIUM

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.