CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-55079
4.9 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.24.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `NewDataBuilder` in …

Jul 8, 2026
CVE-2026-55078
6.5 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.17.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `POST /api/v2/files` …

Jul 7, 2026
CVE-2026-50811
6.5 MEDIUM

An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates

Jul 7, 2026
CVE-2026-50810
5.5 MEDIUM

A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master HEAD before commit b35c61f104b85fbb16520ac2838d5d2ef70845b5 allows attackers to cause a denial of service

Jul 7, 2026
CVE-2026-36163
5.4 MEDIUM

An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execute arbitrary JavaScript in the context of the victim's …

Jul 7, 2026
CVE-2026-36162
5.4 MEDIUM

An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute arbitrary Javascript or HTML via …

Jul 7, 2026
CVE-2026-58266
6.5 MEDIUM

Anki is a program for creating and reviewing flashcards. Prior to 25.09.4, Anki's webview-based pages communicate with the Rust backend using an internal localhost API, …

Jul 7, 2026
CVE-2026-55490
6.5 MEDIUM

OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated attacker …

Jul 7, 2026
CVE-2026-54601
6.3 MEDIUM

FastGPT is an open source AI knowledge base platform. From 4.14.17 to before 4.15.0-beta4, FastGPT allows an authenticated tenant user to call POST /api/core/dataset/collection/create/reTrainingCollection in …

Jul 7, 2026
CVE-2026-50179
4.2 MEDIUM

Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/src/server/transactions/export/export-to-csv.ts pass user-controlled Payee, Notes, Account, and Category strings to csv-stringify …

Jul 7, 2026
CVE-2026-45796
6.5 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 are vulnerable to unauthenticated semi-blind …

Jul 7, 2026
CVE-2026-58472
5.9 MEDIUM

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker …

Jul 7, 2026
CVE-2026-58471
5.9 MEDIUM

GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to …

Jul 7, 2026
CVE-2026-58470
5.3 MEDIUM

GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause …

Jul 7, 2026
CVE-2026-55434
6.5 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.33.0 and prior to versions 2.33.8 and 2.34.2, AI Bridge provider handlers …

Jul 7, 2026
CVE-2026-53935
6.9 MEDIUM

Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to …

Jul 7, 2026
CVE-2026-46700
4.3 MEDIUM

Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-server checks only that the caller has a valid session …

Jul 7, 2026
CVE-2026-46672
4.6 MEDIUM

Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in packages/cli/src/output.ts used whenever the global --format csv option …

Jul 7, 2026
CVE-2026-58468
5.5 MEDIUM

NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows authenticated administrators to issue arbitrary outbound HTTP requests by supplying …

Jul 7, 2026
CVE-2026-44877
6.5 MEDIUM

An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful exploitation of this vulnerability could allow …

Jul 7, 2026
CVE-2026-55435
5.4 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy …

Jul 7, 2026
CVE-2026-48956
5.0 MEDIUM

An improper access check allows users to display a list of modules in the frontend.

Jul 7, 2026
CVE-2026-48955
6.5 MEDIUM

An improper access check allows unauthorized users to access workflow stage and transition information.

Jul 7, 2026
CVE-2026-48954
6.1 MEDIUM

Improper validation leads to a generic XSS vector in the language override feature.

Jul 7, 2026
CVE-2026-48953
6.1 MEDIUM

Lack of escaping leads to an XSS vulnerability in the generic image output layout.

Jul 7, 2026
CVE-2026-48952
6.1 MEDIUM

Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.

Jul 7, 2026
CVE-2026-48951
6.1 MEDIUM

Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.

Jul 7, 2026
CVE-2026-48950
6.1 MEDIUM

Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.

Jul 7, 2026
CVE-2026-48949
6.1 MEDIUM

Lack of validation leads to an XSS vulnerability in the MFA management views.

Jul 7, 2026
CVE-2026-48947
4.9 MEDIUM

An improper access check allows privileged users to overwrite media files without editing permissions.

Jul 7, 2026
CVE-2026-14904
6.5 MEDIUM

AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources …

Jul 7, 2026
CVE-2025-12799
6.5 MEDIUM

A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped characters …

Jul 7, 2026
CVE-2026-14969
4.4 MEDIUM

A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an …

Jul 7, 2026
CVE-2026-59709
4.3 MEDIUM

Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. Attackers with …

Jul 7, 2026
CVE-2026-53878
6.1 MEDIUM

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a …

Jul 7, 2026
CVE-2026-53877
4.8 MEDIUM

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which …

Jul 7, 2026
CVE-2026-14940
5.3 MEDIUM

A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued nested …

Jul 7, 2026
CVE-2026-12352
5.9 MEDIUM

This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device.

Jul 7, 2026
CVE-2026-10659
4.7 MEDIUM

The Dhara flash translation layer disk driver (drivers/disk/ftl_dhara.c) implemented the dhara_nand_ callbacks so that, on a flash error, the error code was written unconditionally through …

Jul 7, 2026
CVE-2026-49487
6.5 MEDIUM

In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When a deferred operator …

Jul 7, 2026
CVE-2026-49296
6.5 MEDIUM

Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` …

Jul 7, 2026
CVE-2026-48892
6.5 MEDIUM

The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options whose option names were not …

Jul 7, 2026
CVE-2026-48891
4.3 MEDIUM

A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag …

Jul 7, 2026
CVE-2026-48828
6.5 MEDIUM

The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key …

Jul 7, 2026
CVE-2026-14868
5.5 MEDIUM

The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, …

Jul 7, 2026
CVE-2026-14867
5.5 MEDIUM

Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.0. A local attacker could retrieve users’ …

Jul 7, 2026
CVE-2026-13199
4.0 MEDIUM

EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. This resulted in consistent kernel addresses across …

Jul 7, 2026
CVE-2026-8309
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Reflected XSS. This …

Jul 7, 2026
CVE-2026-8306
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Stored XSS. This …

Jul 7, 2026
CVE-2026-7380
6.1 MEDIUM

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows XSS …

Jul 7, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.