CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-58315
4.3 MEDIUM

Cross-site request forgery vulnerability exists in SEIKO EPSON Web Config. If a user views a malicious page while logged into Web Config, unintended operations may …

Jul 7, 2026
CVE-2026-10834
4.6 MEDIUM

The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile image path before moving the file, allowing …

Jul 7, 2026
CVE-2026-26053
5.3 MEDIUM

An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to perform some operations that they would …

Jul 7, 2026
CVE-2026-42147
4.9 MEDIUM

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, S3 storage endpoint validation only checks URL format and …

Jul 7, 2026
CVE-2026-34198
5.3 MEDIUM

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the TrustProxies middleware trusts all proxies ($proxies = '*'), …

Jul 7, 2026
CVE-2026-34170
4.3 MEDIUM

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the GithubApp api_url field is used as the base …

Jul 7, 2026
CVE-2026-11328
6.4 MEDIUM

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title parameter in all versions up to, and …

Jul 7, 2026
CVE-2026-13356
6.3 MEDIUM

A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin in the …

Jul 7, 2026
CVE-2024-56141
5.0 MEDIUM

Minosoft is an open-source, multi-version Minecraft Java Edition client written in Kotlin. Starting in commit f1ae30e2b046a490026a8413b075685deb795122, the CryptManager encryption routine ( CryptManager.kt ) initializes its …

Jul 7, 2026
CVE-2026-59710
6.1 MEDIUM

showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/tables.js that fails to properly escape table header ID attributes. Attackers can inject …

Jul 6, 2026
CVE-2026-41899
6.5 MEDIUM

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, POST /api/feedback has no authentication, no rate limiting, and …

Jul 6, 2026
CVE-2026-38979
5.4 MEDIUM

ajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI. In ajenti-core/aj/http.py, the core HTTP response path initializes an empty header …

Jul 6, 2026
CVE-2026-38973
4.4 MEDIUM

mrubyc through release3.4.1 was found to contain an out-of-bounds read in builtin missing-method lookup inside mrbc_find_method().

Jul 6, 2026
CVE-2026-34167
5.0 MEDIUM

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the ActivityMonitor Livewire component exposes a public $activityId property …

Jul 6, 2026
CVE-2026-34050
6.5 MEDIUM

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the Settings/Updates Livewire component does not check isInstanceAdmin in …

Jul 6, 2026
CVE-2026-32718
6.5 MEDIUM

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, mutating API validation endpoints are guarded by read ability, …

Jul 6, 2026
CVE-2026-59711
6.1 MEDIUM

showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitrary HTML and JavaScript. When completeHTMLDocument option is enabled, unescaped …

Jul 6, 2026
CVE-2026-55514
6.5 MEDIUM

vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a /v1/completions request with …

Jul 6, 2026
CVE-2026-54764
5.8 MEDIUM

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middleware, even when configured with trustForwardHeader: false, derives …

Jul 6, 2026
CVE-2026-50135
5.5 MEDIUM

Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made RootMappingFs.statRoot use Stat (follows symlinks) instead of Lstat , so a direct …

Jul 6, 2026
CVE-2026-48267
5.5 MEDIUM

DNG SDK versions 1.7.1 2536 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Jul 6, 2026
CVE-2026-21384
5.3 MEDIUM

Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.

Jul 6, 2026
CVE-2026-21370
5.3 MEDIUM

Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.

Jul 6, 2026
CVE-2026-21369
5.3 MEDIUM

Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.

Jul 6, 2026
CVE-2026-21368
5.3 MEDIUM

Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.

Jul 6, 2026
CVE-2025-59617
6.6 MEDIUM

Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.

Jul 6, 2026
CVE-2025-59616
6.6 MEDIUM

Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory.

Jul 6, 2026
CVE-2025-59615
6.6 MEDIUM

Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper synchronization.

Jul 6, 2026
CVE-2026-59089
5.5 MEDIUM

A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calculates the size of the Color Look-Up Table …

Jul 6, 2026
CVE-2026-58404
6.8 MEDIUM

Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests to loopback, internal, and cloud-metadata IPv4 literals, but the …

Jul 6, 2026
CVE-2026-58403
6.5 MEDIUM

Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's virtual filesystem is designed so that files under a mount cannot reach outside the …

Jul 6, 2026
CVE-2026-58402
5.4 MEDIUM

Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-fence language or info-string into the code class="language-…" …

Jul 6, 2026
CVE-2026-55646
6.5 MEDIUM

vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions and /v1/audio/translations routes call request.file.read() to fully materialize …

Jul 6, 2026
CVE-2026-50134
5.8 MEDIUM

Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.http.urls on the URL it is called with, but it did not re-validate …

Jul 6, 2026
CVE-2026-50133
6.1 MEDIUM

Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to the text/html media type (typically …

Jul 6, 2026
CVE-2026-44362
5.5 MEDIUM

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting …

Jul 6, 2026
CVE-2026-14898
6.5 MEDIUM

The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could place an indirect prompt injection in …

Jul 6, 2026
CVE-2026-55798
4.5 MEDIUM

Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without …

Jul 6, 2026
CVE-2026-54291
5.9 MEDIUM

pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to …

Jul 6, 2026
CVE-2026-12154
6.4 MEDIUM

The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attribute of the [fbrev] …

Jul 6, 2026
CVE-2026-40257
5.5 MEDIUM

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting …

Jul 6, 2026
CVE-2026-59152
5.0 MEDIUM

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can send an HTTP request to a server …

Jul 6, 2026
CVE-2026-58203
5.3 MEDIUM

pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource reads secret values from files in a configured secrets_dir. When secrets_nested_subdir=True, a directory entry …

Jul 6, 2026
CVE-2026-13122
5.3 MEDIUM

OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers …

Jul 6, 2026
CVE-2026-44936
5.0 MEDIUM

Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 before 0.14.6, …

Jul 6, 2026
CVE-2025-8591
6.1 MEDIUM

The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an …

Jul 6, 2026
CVE-2026-56139
5.3 MEDIUM

Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Undertow Component. The camel-undertow HTTP server consumer exposes a muteException option that controls what …

Jul 6, 2026
CVE-2026-49365
5.3 MEDIUM

Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty HTTP component. The camel-netty-http HTTP server consumer exposes a muteException option that controls …

Jul 6, 2026
CVE-2026-49099
5.3 MEDIUM

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Salesforce Component. The …

Jul 6, 2026
CVE-2026-49098
5.3 MEDIUM

Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Kafka Component. The camel-kafka producer …

Jul 6, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.