CVE Database

115314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-39834
9.1 CRITICAL

When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused …

May 22, 2026
CVE-2026-39833
9.1 CRITICAL

The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, …

May 22, 2026
CVE-2026-39832
9.1 CRITICAL

When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when …

May 22, 2026
CVE-2026-39831
9.1 CRITICAL

The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing …

May 22, 2026
CVE-2026-39830
9.1 CRITICAL

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not …

May 22, 2026
CVE-2026-39829
7.5 HIGH

The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or …

May 22, 2026
CVE-2026-39828
6.3 MEDIUM

When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a …

May 22, 2026
CVE-2026-39827
6.5 MEDIUM

An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting …

May 22, 2026
CVE-2026-9264
9.3 CRITICAL

A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The …

May 22, 2026
CVE-2026-34911
7.7 HIGH

A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files …

May 22, 2026
CVE-2026-34910
10.0 CRITICAL KEV

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

May 22, 2026
CVE-2026-34909
10.0 CRITICAL KEV

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying …

May 22, 2026
CVE-2026-34908
10.0 CRITICAL KEV

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to …

May 22, 2026
CVE-2026-33000
9.1 CRITICAL

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute …

May 22, 2026
CVE-2026-5297

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 21, 2026
CVE-2026-8435
6.5 MEDIUM

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion(). The Concrete CMS security team gave this vulnerability a …

May 21, 2026
CVE-2026-8434
8.8 HIGH

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple(). The Concrete CMS security team gave this vulnerability a …

May 21, 2026
CVE-2026-8433
8.8 HIGH

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan(). The Concrete CMS security team gave this vulnerability a …

May 21, 2026
CVE-2026-8432
8.8 HIGH

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star(). The Concrete CMS security team gave this vulnerability a …

May 21, 2026
CVE-2026-8427
8.8 HIGH

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id). The Concrete CMS security team gave this vulnerability a …

May 21, 2026
CVE-2026-8416
8.8 HIGH

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id). The Concrete CMS security team gave this vulnerability a …

May 21, 2026
CVE-2026-8415
8.8 HIGH

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder. The Concrete CMS security team gave this vulnerability a CVSS …

May 21, 2026
CVE-2026-8414
8.8 HIGH

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate. The Concrete CMS security team gave this vulnerability a CVSS …

May 21, 2026
CVE-2026-8413
8.8 HIGH

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design. The Concrete CMS security team gave this vulnerability a CVSS …

May 21, 2026
CVE-2026-8412
8.8 HIGH

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache. The Concrete CMS security team gave this vulnerability a CVSS …

May 21, 2026
CVE-2026-8411
8.8 HIGH

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete. The Concrete CMS security team gave this vulnerability a CVSS …

May 21, 2026
CVE-2026-8410
8.8 HIGH

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete. The The Concrete CMS security team gave this vulnerability a …

May 21, 2026
CVE-2026-8409
8.8 HIGH

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete. The The Concrete CMS security team gave this vulnerability a …

May 21, 2026
CVE-2026-8337
5.3 MEDIUM

Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in such a way …

May 21, 2026
CVE-2026-8327
4.3 MEDIUM

Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass. The user-profile edit controller passes the entire raw POST …

May 21, 2026
CVE-2026-8245
5.4 MEDIUM

Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection. Concrete\Core\Legacy\Pagination builds pagination links by raw-interpolating its $URL …

May 21, 2026
CVE-2026-8240
5.3 MEDIUM

Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure across every page with a configured summary template, revealing the existence of private, …

May 21, 2026
CVE-2026-8239
5.3 MEDIUM

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/get_rating' endpoint confirms existence and returns rating score for any message by ID. The Concrete …

May 21, 2026
CVE-2026-8238
5.3 MEDIUM

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/message_page' endpoint returns the full content of any conversation message. An unauthenticated attacker can enumerate …

May 21, 2026
CVE-2026-8237
5.3 MEDIUM

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail` endpoint returns the full content of any conversation message. An unauthenticated attacker can enumerate …

May 21, 2026
CVE-2026-8236
4.3 MEDIUM

Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate. The endpoint /ccm/system/dialogs/file/usage/{fID} accepts an integer file ID in the …

May 21, 2026
CVE-2026-8139
5.4 MEDIUM

Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExternal bypasses being sanitized. The Concrete CMS security team gave …

May 21, 2026
CVE-2026-7890
6.4 MEDIUM

In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation enabling …

May 21, 2026
CVE-2026-7887
6.4 MEDIUM

For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A user with uIsActive=0 (suspended, banned, terminated employee) can still authenticate via …

May 21, 2026
CVE-2026-7886
4.3 MEDIUM

Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter which can lead to file permission bypass. The `AddMessage` and `UpdateMessage` …

May 21, 2026
CVE-2026-7882
4.3 MEDIUM

Concrete CMS 9.5.0 and below is vulnerable to unauthorized file deletion due to an Inverted CSRF token check in the DeleteFile controller. The code throws …

May 21, 2026
CVE-2026-7881
4.3 MEDIUM

Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block via the exEntryID parameter. This IDOR …

May 21, 2026
CVE-2026-7879
5.3 MEDIUM

In Concrete CMS 9.5.0 and below, the submit_password() method in concrete/controllers/single_page/download_file.php allows unauthorized file access since downloading permission-restricted files bypasses the view_file permission check. Files …

May 21, 2026
CVE-2026-6960
9.8 CRITICAL

The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in all versions …

May 21, 2026
CVE-2026-5091
5.1 MEDIUM

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to …

May 21, 2026
CVE-2026-4929

Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper output escaping of term-derived text. Confirmed affected paths include field formatter …

May 21, 2026
CVE-2026-4093

In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter rendering pipeline. Vector A (token display templates): When the …

May 21, 2026
CVE-2026-22678
5.4 MEDIUM

Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status module that allows low-privileged …

May 21, 2026
CVE-2026-8428
8.8 HIGH

Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but the corresponding do_update() method in concrete/controllers/single_page/dashboard/system/update/update.php never calls $this->token->validate('do_update'). The …

May 21, 2026
CVE-2026-8426
8.8 HIGH

Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepare_remote_upgrade/<remoteMPID>. An attacker who controls the remote package returned for …

May 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.