CVE Database

57293+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-84501
5.3 MEDIUM

An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted add_auth("ensemble", ...) request containing newline characters (\n). …

Sep 16, 2026
CVE-2026-77190
6.5 MEDIUM

On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to connect to a device with PIM Sparse …

Sep 16, 2026
CVE-2026-73469
5.8 MEDIUM

When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended …

Sep 16, 2026
CVE-2026-73468
6.5 MEDIUM

A specially crafted packet can cause the premature expiry of multicast forwarding state on affected interfaces, potentially resulting in temporary multicast traffic loss during the …

Sep 16, 2026
CVE-2026-73440
4.2 MEDIUM

On affected platforms running Arista EOS with Simple Network Management Protocol (SNMP) configured, SNMPv3 local or remote user credentials may be exposed as a one-way …

Sep 16, 2026
CVE-2026-73438
5.3 MEDIUM

On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, an unauthenticated attacker on the same OSPFv3 broadcast domain can …

Sep 16, 2026
CVE-2026-73436
6.5 MEDIUM

On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause …

Sep 16, 2026
CVE-2026-19640
4.2 MEDIUM

On affected platforms running Arista EOS, an authenticated user with access to the gNMI (gRPC Network Management Interface) may receive incorrect authorization results, potentially allowing …

Sep 16, 2026
CVE-2026-92081
5.9 MEDIUM

fastify is a fast and low-overhead web framework for Node.js. In versions before 5.12.5, when a route registers a response trailer via reply.trailer() and is …

Sep 16, 2026
CVE-2026-85501
5.3 MEDIUM

Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones …

Sep 16, 2026
CVE-2026-82720
5.9 MEDIUM

NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., …

Sep 16, 2026
CVE-2026-80225
5.3 MEDIUM

In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit …

Sep 16, 2026
CVE-2026-78227
6.5 MEDIUM

NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'. Each DoQ stream owns an …

Sep 16, 2026
CVE-2026-77955
4.4 MEDIUM

In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) …

Sep 16, 2026
CVE-2026-73463
5.3 MEDIUM

On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may …

Sep 16, 2026
CVE-2026-73445
4.9 MEDIUM

On affected platforms running Arista EOS, an issue with the gRPC Network Security Interface (gNSI) Authz Rotate RPC may cause an incorrect Authz policy which …

Sep 16, 2026
CVE-2026-92091
5.9 MEDIUM

A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexity, and …

Sep 16, 2026
CVE-2026-89207
6.5 MEDIUM

A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (All versions < V4.17). Affected devices do not properly …

Sep 16, 2026
CVE-2026-86341
4.4 MEDIUM

GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain …

Sep 16, 2026
CVE-2026-81326
5.5 MEDIUM

QND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the affected product's client …

Sep 16, 2026
CVE-2026-27553
6.5 MEDIUM

A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password …

Sep 16, 2026
CVE-2026-8030
4.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain …

Sep 16, 2026
CVE-2026-86475
5.3 MEDIUM

The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission against the capacity configured for its own slot, …

Sep 16, 2026
CVE-2026-84906
5.3 MEDIUM

The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the …

Sep 16, 2026
CVE-2026-7514
4.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that an authenticated …

Sep 16, 2026
CVE-2026-19857
4.8 MEDIUM

The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortcode parser when it substitutes a supported token …

Sep 16, 2026
CVE-2026-19619
4.7 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain …

Sep 16, 2026
CVE-2026-16794
4.3 MEDIUM

GitLab has remediated an issue in GitLab EE affecting all versions from 18.11 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain …

Sep 16, 2026
CVE-2026-13407
5.4 MEDIUM

The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the …

Sep 16, 2026
CVE-2024-11222
6.4 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain …

Sep 16, 2026
CVE-2026-92358
6.4 MEDIUM

A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a different browser, a temporary …

Sep 16, 2026
CVE-2026-5920
6.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' parameter of the bt_bb_shortcode shortcode in all versions up …

Sep 16, 2026
CVE-2026-18555
6.1 MEDIUM

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the …

Sep 16, 2026
CVE-2026-16588
6.5 MEDIUM

The WP Directory Kit plugin for WordPress is vulnerable to blind SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.5.4 …

Sep 16, 2026
CVE-2026-11996
6.4 MEDIUM

The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' Field in all versions up to, and including, 1.2.3 …

Sep 16, 2026
CVE-2026-11984
5.3 MEDIUM

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 …

Sep 16, 2026
CVE-2026-92247
4.7 MEDIUM

A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename of the file admin/file-manager.php of the component Admin …

Sep 16, 2026
CVE-2026-92221
4.7 MEDIUM

A vulnerability was determined in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this vulnerability is the function generate_index_pasien of the file application/models/app_global_admin_model.php. Executing a manipulation …

Sep 16, 2026
CVE-2026-92220
5.3 MEDIUM

A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_finished/MoRIIOConnectorWorker.get_finished/MoRIIOWrapper._handle_release_message of the file vllm/distributed/kv_transfer/kv_connector/v1/moriio/moriio_connector.py of the component MoRIIO Acknowledgement Handler. Performing a …

Sep 16, 2026
CVE-2026-86109
6.6 MEDIUM

The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used …

Sep 16, 2026
CVE-2026-73450
6.9 MEDIUM

On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can …

Sep 16, 2026
CVE-2026-92298
4.8 MEDIUM

EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and campaign URLs instead of a cryptographically secure generator. Remote …

Sep 16, 2026
CVE-2026-92217
6.3 MEDIUM

A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/web_core/src/v0_9/processing/message-processor.ts of the component Message Parsing. This …

Sep 16, 2026
CVE-2026-92216
4.3 MEDIUM

A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/generic-binder.ts of the component …

Sep 16, 2026
CVE-2026-92213
5.5 MEDIUM

A vulnerability was detected in a2ui-project a2ui up to 0.10.6. This impacts the function z.any of the file renderers/web_core/src/v0_9/schema/server-to-client.ts of the component Angular Renderer. Performing …

Sep 16, 2026
CVE-2026-92184
6.3 MEDIUM

A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component Multimodal Content. The …

Sep 16, 2026
CVE-2026-73460
6.1 MEDIUM

On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause …

Sep 16, 2026
CVE-2025-11395
5.5 MEDIUM

A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on …

Sep 15, 2026
CVE-2026-92259
5.5 MEDIUM

Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the bytecode-cache directory to cause a heap-based buffer overflow and …

Sep 15, 2026
CVE-2026-92257
5.4 MEDIUM

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval() sinks, affecting the call board text and …

Sep 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.