CVE Database

57293+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-52307
5.4 MEDIUM

An authenticated stored cross-site scripting (XSS) vulnerability in the Column Management component of ClassCMS 1CMS v5.6 allows attackers to execute arbitrary web scripts or HTML …

Sep 8, 2026
CVE-2026-22575
4.9 MEDIUM

An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager …

Sep 8, 2026
CVE-2026-86853
4.3 MEDIUM

A malicious webpage could repeatedly trigger external URL schemes, causing system prompts or external application launches. This could make Firefox for iOS temporarily unusable until …

Sep 8, 2026
CVE-2026-86737
4.3 MEDIUM

snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. Authenticated attackers can iterate asset IDs to retrieve barcodes and …

Sep 8, 2026
CVE-2026-86736
4.3 MEDIUM

snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations …

Sep 8, 2026
CVE-2026-86735
5.0 MEDIUM

snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fails to detect IPv6 transition addresses encoding private IPv4 …

Sep 8, 2026
CVE-2026-86734
6.5 MEDIUM

Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST /account/accept/{acceptance} endpoint, allowing authenticated users to submit unbounded input that …

Sep 8, 2026
CVE-2026-86731
6.5 MEDIUM

Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-target guard in UsersController::actionActivateUser (the users/activate-user action). While the action requires the administrateUsers permission, it does …

Sep 8, 2026
CVE-2026-86726
6.5 MEDIUM

AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php that allows authenticated streamers to enumerate source stream keys and identities of all other streamers' …

Sep 8, 2026
CVE-2026-86724
6.5 MEDIUM

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in plugin/YPTWallet/view/saveBalance.php that allows attackers to set arbitrary wallet balances by relying only on session …

Sep 8, 2026
CVE-2026-86719
5.4 MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master) contains a cross-site request forgery vulnerability in the CustomizeUser plugin endpoint plugin/CustomizeUser/swapUser.json.php. The endpoint takes users_id from $_REQUEST and …

Sep 8, 2026
CVE-2026-79573
6.5 MEDIUM

L-ONE v1.0.0 was discovered to contain multiple SQL injection vulnerabilities in the /attachment/getBusinessUploadList component via the busid, id, and taskid parameters. This vulnerability allows attackers …

Sep 8, 2026
CVE-2026-56101
5.3 MEDIUM

OpenBSD before commit 1ee99df contains an inverted comparison vulnerability in the ieee80211_michael_mic_failure() function within sys/net80211/ieee80211_crypto_tkip.c that allows unauthenticated attackers within RF range to trigger denial …

Sep 8, 2026
CVE-2026-84282
6.5 MEDIUM

A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The /apps/onlyoffice/ajax/settings/address endpoint does not sufficiently validate the user-supplied Document …

Sep 8, 2026
CVE-2026-12387
5.1 MEDIUM

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel …

Sep 8, 2026
CVE-2026-12285
4.0 MEDIUM

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel …

Sep 8, 2026
CVE-2026-11891
5.1 MEDIUM

Use After Free vulnerability in Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process …

Sep 8, 2026
CVE-2026-0001
4.4 MEDIUM

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel …

Sep 8, 2026
CVE-2026-79379
6.5 MEDIUM

A buffer overflow in the SBC_DecodeFrames() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier and fixed in v.5.0 allows attackers …

Sep 8, 2026
CVE-2026-78838
6.5 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the grid_datasource.php component of AppNitro MachForm v30 allows attackers to execute arbitrary Javascript in the context of the …

Sep 8, 2026
CVE-2026-73321
6.5 MEDIUM

XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that allows authenticated attackers to cause persistent denial of service by submitting a …

Sep 8, 2026
CVE-2026-73320
6.1 MEDIUM

XenForo before 2.3.13 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private unfurl records by supplying predictable auto-increment primary key IDs …

Sep 8, 2026
CVE-2026-73319
6.1 MEDIUM

XenForo before 2.3.13 contains a cross-site scripting vulnerability in the dynamic redirect handler that allows unauthenticated attackers to execute arbitrary JavaScript in the board origin …

Sep 8, 2026
CVE-2026-73313
6.8 MEDIUM

XenForo before 2.3.13 contains a multi-factor authentication bypass vulnerability in the passkey TFA provider that allows an authenticated attacker to complete login as another user …

Sep 8, 2026
CVE-2026-73310
5.9 MEDIUM

XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding …

Sep 8, 2026
CVE-2026-33391
5.4 MEDIUM

An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges …

Sep 8, 2026
CVE-2026-33387
4.6 MEDIUM

A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges …

Sep 8, 2026
CVE-2026-79603
4.3 MEDIUM

x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen …

Sep 8, 2026
CVE-2026-62437
6.5 MEDIUM

When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assigned to guests, and the associated …

Sep 8, 2026
CVE-2026-86714
5.4 MEDIUM

PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply …

Sep 8, 2026
CVE-2026-76931
6.4 MEDIUM

The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 3.3.205 …

Sep 8, 2026
CVE-2026-2520
5.4 MEDIUM

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Sep 8, 2026
CVE-2026-18021
6.5 MEDIUM

The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up …

Sep 8, 2026
CVE-2026-17509
6.5 MEDIUM

The WPML Multilingual CMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘elementIds’ parameter in all versions up to, and including, 4.9.5 …

Sep 8, 2026
CVE-2026-12230
6.4 MEDIUM

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout_custom_css' parameter …

Sep 8, 2026
CVE-2026-86597
6.5 MEDIUM

Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, …

Sep 8, 2026
CVE-2026-86550
6.5 MEDIUM

NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This results in a universal …

Sep 8, 2026
CVE-2026-74859
6.8 MEDIUM

The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files …

Sep 8, 2026
CVE-2026-62654
6.8 MEDIUM

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance mode can be activated via a physical key sequence during …

Sep 8, 2026
CVE-2026-62653
6.8 MEDIUM

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The input received over a proprietary communication protocol that is exposed when the …

Sep 8, 2026
CVE-2026-62652
5.3 MEDIUM

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from which debugging symbols have not been removed. …

Sep 8, 2026
CVE-2026-58113
6.1 MEDIUM

A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter …

Sep 8, 2026
CVE-2026-81802
6.5 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions.

Sep 8, 2026
CVE-2026-81792
6.5 MEDIUM

Unauthenticated Privilege Escalation in Product Catalog Enquiry for WooCommerce by MultiVendorX <= 6.1.4 versions.

Sep 8, 2026
CVE-2026-86519
5.3 MEDIUM

A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handler. …

Sep 8, 2026
CVE-2026-86518
6.3 MEDIUM

A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument …

Sep 8, 2026
CVE-2026-86517
6.3 MEDIUM

A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of the file /pages/us_searchfrm.php. Executing a …

Sep 8, 2026
CVE-2026-86516
4.7 MEDIUM

A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC …

Sep 8, 2026
CVE-2026-86515
4.3 MEDIUM

A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such …

Sep 8, 2026
CVE-2026-86514
6.3 MEDIUM

A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This …

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.