CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-14658
6.3 MEDIUM

A vulnerability was detected in code-projects Assessment Management 1.0. This vulnerability affects unknown code of the file /lecturer/marking-scheme.php. The manipulation of the argument smarksrange[] results …

Jul 4, 2026
CVE-2026-14657
6.3 MEDIUM

A flaw has been found in code-projects Assessment Management 1.0. This issue affects some unknown processing of the file /lecturer/marking-scheme.php of the component Database Query …

Jul 4, 2026
CVE-2026-14656
4.3 MEDIUM

A security vulnerability has been detected in code-projects Assessment Management 1.0. This affects an unknown part of the file /admin/remove-user.php. The manipulation of the argument …

Jul 4, 2026
CVE-2024-1248
4.8 MEDIUM

The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a …

Jul 4, 2026
CVE-2026-14647
4.3 MEDIUM

A weakness has been identified in onnx up to 1.21.x. This vulnerability affects the function convPoolShapeInference_opset19 of the file onnx/defs/nn/old.cc of the component onnxruntime. This …

Jul 4, 2026
CVE-2026-14639
6.3 MEDIUM

A vulnerability has been found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /ecommerce-website-php/customer/my_account.php?edit_account. Such manipulation of the argument c_name …

Jul 4, 2026
CVE-2026-14638
6.3 MEDIUM

A flaw has been found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /patient.php. This manipulation of the argument …

Jul 4, 2026
CVE-2026-14636
5.4 MEDIUM

A weakness has been identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 23105f25dadf57b4314fc015a63a7c6e910c89df. Impacted is the function do_upload_others_images of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Image …

Jul 4, 2026
CVE-2026-14634
4.3 MEDIUM

A vulnerability was identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 213babdbaa949e94557246414db0130e01394517. This vulnerability affects the function checkForPostRequests of the file application/core/MY_Controller.php of the component Subscribed Emails …

Jul 4, 2026
CVE-2026-14633
4.3 MEDIUM

A vulnerability was determined in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 49b20f53de2b7ec34e920b11c863f1491d911a04. This affects an unknown part of the file /index.php/api/product/set of the component Hidden REST API …

Jul 4, 2026
CVE-2026-14632
4.3 MEDIUM

A vulnerability was found in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 95dfa8cebbb87ab46ae450643a07241274a74dce. Affected by this issue is the function setReferrer of the file application/core/MY_Controller.php of the component …

Jul 4, 2026
CVE-2026-14629
4.3 MEDIUM

A flaw has been found in RT-Thread up to 5.2.2. Affected is the function read/write/sys_ioctl of the file components/lwp/lwp_syscall.c of the component Parameter Handler. Executing …

Jul 4, 2026
CVE-2026-14628
5.3 MEDIUM

A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of the file gateway/platforms/base.py of the component Live Webhook Endpoint. …

Jul 4, 2026
CVE-2026-14627
5.6 MEDIUM

A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2. This affects the function DiscordAdapter._is_allowed_user of the file gateway/platforms/discord.py of the component Discord …

Jul 4, 2026
CVE-2026-14626
4.3 MEDIUM

A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. The impacted element is the function AIAgent.run_conversation of the file run_agent.py of the component …

Jul 4, 2026
CVE-2026-14625
6.3 MEDIUM

A security flaw has been discovered in NousResearch hermes-agent up to 0.15.2. The affected element is the function shell.exec of the file tui_gateway/server.py. The manipulation …

Jul 4, 2026
CVE-2026-14624
4.3 MEDIUM

A vulnerability was identified in omec-project amf up to 2.0.2/2.1.1. Impacted is an unknown function of the file /go/src/amf/ngap/handler.go of the component NGSetupRequest Handler. The …

Jul 4, 2026
CVE-2026-14623
4.3 MEDIUM

A vulnerability was determined in omec-project amf up to 2.1.1. This issue affects the function RRCInactiveTransitionReport of the component NGAP Message Handler. Executing a manipulation …

Jul 4, 2026
CVE-2026-14619
6.3 MEDIUM

A flaw has been found in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /medicine.php. This manipulation …

Jul 4, 2026
CVE-2026-14618
4.3 MEDIUM

A vulnerability was detected in Open5GS up to 2.7.7. Affected by this vulnerability is the function amf_nnrf_handle_nf_discover of the file src/amf/nnrf-handler.c of the component AMF. …

Jul 4, 2026
CVE-2026-58523
6.5 MEDIUM

Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.

Jul 3, 2026
CVE-2026-58597
4.3 MEDIUM

Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Jul 3, 2026
CVE-2026-58524
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Jul 3, 2026
CVE-2026-58522
6.8 MEDIUM

Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

Jul 3, 2026
CVE-2026-58418
6.5 MEDIUM

SSRF via HTTP Redirect in Repository Migration

Jul 3, 2026
CVE-2026-58300
6.2 MEDIUM

Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

Jul 3, 2026
CVE-2026-58291
6.1 MEDIUM

Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Jul 3, 2026
CVE-2026-58278
5.4 MEDIUM

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Jul 3, 2026
CVE-2026-57987
6.5 MEDIUM

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Jul 3, 2026
CVE-2026-56646
6.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Jul 3, 2026
CVE-2026-55945
4.2 MEDIUM

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.

Jul 3, 2026
CVE-2026-45489
6.5 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Jul 3, 2026
CVE-2026-45488
5.4 MEDIUM

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Jul 3, 2026
CVE-2026-28705
5.3 MEDIUM

Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect …

Jul 3, 2026
CVE-2026-27783
4.3 MEDIUM

Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.

Jul 3, 2026
CVE-2026-27761
4.3 MEDIUM

Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit …

Jul 3, 2026
CVE-2026-25782
5.3 MEDIUM

Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion attempts …

Jul 3, 2026
CVE-2026-25779
6.1 MEDIUM

Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect_to values.

Jul 3, 2026
CVE-2026-25714
4.3 MEDIUM

Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization API, leaving an incomplete fix for CVE-2025-68941.

Jul 3, 2026
CVE-2026-20909
5.3 MEDIUM

Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.

Jul 3, 2026
CVE-2026-14611
4.3 MEDIUM

A vulnerability has been found in DeepMyst Mysti up to 0.4.0. The affected element is the function initProjectMemory of the file src/managers/MemoryManager.ts of the component …

Jul 3, 2026
CVE-2026-14610
5.3 MEDIUM

A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the …

Jul 3, 2026
CVE-2026-14609
5.6 MEDIUM

A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue affects some unknown processing. The manipulation results in …

Jul 3, 2026
CVE-2026-14355
5.6 MEDIUM

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer …

Jul 3, 2026
CVE-2026-14608
4.3 MEDIUM

A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file …

Jul 3, 2026
CVE-2026-14607
5.5 MEDIUM

A weakness has been identified in RT-Thread up to 5.0.2. This affects the function sys_getaddrinfo of the file components/lwp/lwp_syscall.c. Executing a manipulation of the argument …

Jul 3, 2026
CVE-2026-14604
6.3 MEDIUM

A vulnerability was determined in Open Asset Import Library Assimp up to 6.0.4. Affected is the function Assimp::Exporter::ExportToBlob of the file code/AssetLib/Ply/PlyLoader.cpp of the component …

Jul 3, 2026
CVE-2026-14631
5.3 MEDIUM

webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request with a malformed Host header …

Jul 3, 2026
CVE-2026-14620
4.7 MEDIUM

webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the …

Jul 3, 2026
CVE-2026-14615
4.3 MEDIUM

A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to …

Jul 3, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.