CVE Database

130945+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-20235
4.9 MEDIUM

A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an affected device. …

Sep 16, 2026
CVE-2026-20222
7.4 HIGH

A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow …

Sep 16, 2026
CVE-2026-20154
8.6 HIGH

A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat …

Sep 16, 2026
CVE-2026-20135
8.6 HIGH

A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected …

Sep 16, 2026
CVE-2026-20121
5.3 MEDIUM

A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure …

Sep 16, 2026
CVE-2026-20120
5.8 MEDIUM

A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure …

Sep 16, 2026
CVE-2026-20072
4.9 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users that are …

Sep 16, 2026
CVE-2026-20071
3.8 LOW

A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco ISE could allow an unauthenticated, adjacent attacker to hijack the onboarding session of another user …

Sep 16, 2026
CVE-2025-56566

MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage. An attacker with physical access to the device can extract …

Sep 16, 2026
CVE-2025-56565

DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in cleartext within non-volatile memory. The exposed material includes SSH …

Sep 16, 2026
CVE-2025-56563

A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts an attacker-controlled address URL parameter and passes it to …

Sep 16, 2026
CVE-2026-92808

A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue …

Sep 16, 2026
CVE-2026-92526
6.3 MEDIUM

A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/leave/index.php. Executing a manipulation of the …

Sep 16, 2026
CVE-2026-92475
5.3 MEDIUM

A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utils/downloader.c. This manipulation of the argument Content-Range causes out-of-bounds …

Sep 16, 2026
CVE-2026-92474
3.3 LOW

A security flaw has been discovered in GPAC 26.08-DEV. This affects the function gf_inline_get_proto_lib of the file src/compositor/mpeg4_inline.c of the component Proto Link Handler. The …

Sep 16, 2026
CVE-2026-89084

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under …

Sep 16, 2026
CVE-2026-89083

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under …

Sep 16, 2026
CVE-2026-89082

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under …

Sep 16, 2026
CVE-2026-88592

kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The cross-origin file proxy endpoint /getCorsFile is protected by TrustHostFilter against the trust.host whitelist. However, …

Sep 16, 2026
CVE-2026-87976

Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR …

Sep 16, 2026
CVE-2026-87116
6.5 MEDIUM

Tanium addressed a server-side request forgery vulnerability in Threat Response.

Sep 16, 2026
CVE-2026-87113
6.3 MEDIUM

Tanium addressed an improper access controls vulnerability in Threat Response.

Sep 16, 2026
CVE-2026-87105
8.8 HIGH

Tanium addressed a SQL injection vulnerability in Threat Response.

Sep 16, 2026
CVE-2026-87076
6.5 MEDIUM

Tanium addressed an information disclosure vulnerability in Discover.

Sep 16, 2026
CVE-2026-87026
3.8 LOW

Tanium addressed an improper access controls vulnerability in Threat Response.

Sep 16, 2026
CVE-2026-87024
7.2 HIGH

Tanium addressed a SQL injection vulnerability in Asset.

Sep 16, 2026
CVE-2026-86865
8.8 HIGH

Tanium addressed a SQL injection vulnerability in Asset.

Sep 16, 2026
CVE-2026-86831
8.7 HIGH

Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an authenticated remote user to bypass NetworkPolicy …

Sep 16, 2026
CVE-2026-86089

Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and …

Sep 16, 2026
CVE-2026-82561

Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process …

Sep 16, 2026
CVE-2026-81870

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively …

Sep 16, 2026
CVE-2026-81866

Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization checking on Assets and Secrets referenced …

Sep 16, 2026
CVE-2026-76646

A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentially resulting in a denial of service condition. Older unsupported versions …

Sep 16, 2026
CVE-2026-76423
10.0 CRITICAL

A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected …

Sep 16, 2026
CVE-2026-70469

Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip …

Sep 16, 2026
CVE-2026-62949
6.5 MEDIUM

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior …

Sep 16, 2026
CVE-2026-20361
8.8 HIGH

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. …

Sep 16, 2026
CVE-2026-20341
9.1 CRITICAL

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenticated, remote attacker to obtain root privileges. This vulnerability is …

Sep 16, 2026
CVE-2026-20330
9.9 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software …

Sep 16, 2026
CVE-2026-20329
9.9 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software …

Sep 16, 2026
CVE-2026-20326
9.8 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. …

Sep 16, 2026
CVE-2026-20325
9.9 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This …

Sep 16, 2026
CVE-2026-20324
9.9 CRITICAL

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary …

Sep 16, 2026
CVE-2026-20322
9.9 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This …

Sep 16, 2026
CVE-2026-20242
9.8 CRITICAL

A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary …

Sep 16, 2026
CVE-2026-20237
9.1 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), …

Sep 16, 2026
CVE-2026-20211
9.1 CRITICAL

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To …

Sep 16, 2026
CVE-2026-20194
9.1 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), …

Sep 16, 2026
CVE-2026-20192
10.0 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) …

Sep 16, 2026
CVE-2026-20176
9.1 CRITICAL

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To …

Sep 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.