CVE Database

11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-52470
9.8 CRITICAL

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml file

Jul 21, 2026
CVE-2026-52469
9.8 CRITICAL

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml file

Jul 21, 2026
CVE-2026-30631
9.8 CRITICAL

An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute arbitrary code via crafted path to `computer_write_file`.

Jul 21, 2026
CVE-2026-64879
9.9 CRITICAL

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and …

Jul 21, 2026
CVE-2026-64878
9.9 CRITICAL

Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via …

Jul 21, 2026
CVE-2026-59147
9.8 CRITICAL

Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find. The attach-time validator dsu_validate_header checks the header …

Jul 21, 2026
CVE-2026-59145
9.1 CRITICAL

Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find. The attach-time validator si_validate_header is thorough …

Jul 21, 2026
CVE-2026-59144
9.8 CRITICAL

Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time validator ring_validate_header checks the capacity-overflow and …

Jul 21, 2026
CVE-2026-50755
9.8 CRITICAL

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value

Jul 21, 2026
CVE-2026-59142
9.1 CRITICAL

Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy. The attach-time validator shm_validate_header checks the …

Jul 21, 2026
CVE-2026-59141
9.1 CRITICAL

Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked. The attach-time validator rdx_validate_header checks the header …

Jul 21, 2026
CVE-2026-59140
9.1 CRITICAL

Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths. The attach-time validator ss_validate_header …

Jul 21, 2026
CVE-2026-59139
9.1 CRITICAL

Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked. The attach-time validator reqrep_validate_header checks the …

Jul 21, 2026
CVE-2016-20096
9.8 CRITICAL

Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the …

Jul 21, 2026
CVE-2026-47416
9.6 CRITICAL

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/members/{user_id}` …

Jul 21, 2026
CVE-2026-47413
9.6 CRITICAL

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST …

Jul 21, 2026
CVE-2026-47410
9.8 CRITICAL

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing …

Jul 21, 2026
CVE-2026-64825
9.3 CRITICAL

Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem …

Jul 21, 2026
CVE-2026-47396
9.8 CRITICAL

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent control API without authentication when `CALL_SERVER_TOKEN` is not …

Jul 21, 2026
CVE-2026-47393
9.8 CRITICAL

PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.generate_api_server_code`) that emits a Flask API server with authentication disabled by …

Jul 21, 2026
CVE-2026-47392
9.9 CRITICAL

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` in `praisonaiagents/tools/python_tools.py` (v1.6.37, subprocess sandbox mode) …

Jul 21, 2026
CVE-2026-47391
9.8 CRITICAL

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC endpoint and registers a `calculate(expression)` …

Jul 21, 2026
CVE-2026-28321
9.1 CRITICAL

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate …

Jul 21, 2026
CVE-2026-28317
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The …

Jul 21, 2026
CVE-2026-28316
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability …

Jul 21, 2026
CVE-2026-28314
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower …

Jul 21, 2026
CVE-2026-28313
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact …

Jul 21, 2026
CVE-2026-28312
9.1 CRITICAL

SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The …

Jul 21, 2026
CVE-2026-28310
9.1 CRITICAL

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. …

Jul 21, 2026
CVE-2026-28309
9.1 CRITICAL

SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in …

Jul 21, 2026
CVE-2026-28308
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The …

Jul 21, 2026
CVE-2026-28307
9.1 CRITICAL

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is …

Jul 21, 2026
CVE-2026-28306
9.1 CRITICAL

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is …

Jul 21, 2026
CVE-2026-28305
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with …

Jul 21, 2026
CVE-2026-28304
9.1 CRITICAL

SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact …

Jul 21, 2026
CVE-2026-28302
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This …

Jul 21, 2026
CVE-2026-65049
9.3 CRITICAL

Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of …

Jul 21, 2026
CVE-2026-65048
9.3 CRITICAL

Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary …

Jul 21, 2026
CVE-2025-66390
9.8 CRITICAL

In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the registration flow …

Jul 21, 2026
CVE-2026-16412
9.8 CRITICAL

Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with …

Jul 21, 2026
CVE-2026-16411
9.8 CRITICAL

Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of …

Jul 21, 2026
CVE-2026-16410
9.8 CRITICAL

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16408
9.8 CRITICAL

Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16407
9.8 CRITICAL

Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16406
9.1 CRITICAL

Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16402
9.8 CRITICAL

Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16395
9.8 CRITICAL

Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16394
9.1 CRITICAL

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16393
9.1 CRITICAL

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16390
9.1 CRITICAL

Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Jul 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.