CVE Database

57293+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-86314
6.2 MEDIUM

Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read …

Sep 7, 2026
CVE-2026-86264
4.3 MEDIUM

A flaw has been found in sfturing ssm_pro up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Endpoint. …

Sep 7, 2026
CVE-2026-86260
6.5 MEDIUM

A security flaw has been discovered in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function modifyPassWord of the file ssm_pro/src/main/java/cn/sfturing/web/CommonUserController.java of the …

Sep 7, 2026
CVE-2026-86245
6.3 MEDIUM

A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_transac.php. Performing a …

Sep 7, 2026
CVE-2026-86244
4.3 MEDIUM

A security vulnerability has been detected in FastAdmin up to 1.2.0.20210401_beta. Affected is the function register/login of the file application/index/controller/User.php of the component User Controller. …

Sep 7, 2026
CVE-2026-86241
4.3 MEDIUM

A weakness has been identified in liufee FeehiCMS up to 2.1.1. This impacts an unknown function of the file environments/prod/backend/config/main-local.php of the component Cookie Validation. …

Sep 7, 2026
CVE-2026-86240
4.7 MEDIUM

A security flaw has been discovered in liufee FeehiCMS up to 2.1.1. This affects the function catchImage of the file backend/widgets/ueditor/Uploader.php of the component UEditor. …

Sep 7, 2026
CVE-2026-86239
5.3 MEDIUM

A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of the file backend/widgets/ueditor/UeditorAction.php of the component UEditor …

Sep 7, 2026
CVE-2026-20518
4.4 MEDIUM

In geniezone, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor …

Sep 7, 2026
CVE-2026-20517
6.7 MEDIUM

In geniezone, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious …

Sep 7, 2026
CVE-2026-20516
5.5 MEDIUM

In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denial of service with User execution …

Sep 7, 2026
CVE-2026-20515
5.5 MEDIUM

In gpu, there is a possible system crash due to use after free. This could lead to local information disclosure with User execution privileges needed. …

Sep 7, 2026
CVE-2026-20514
4.4 MEDIUM

In Audio HAL, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious …

Sep 7, 2026
CVE-2026-20513
4.4 MEDIUM

In Audio HAL, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure if a malicious actor …

Sep 7, 2026
CVE-2026-20512
6.7 MEDIUM

In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a …

Sep 7, 2026
CVE-2026-20511
6.7 MEDIUM

In SurfaceFlinger, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor …

Sep 7, 2026
CVE-2026-20510
6.7 MEDIUM

In camera middleware, there is a possible escalation of privilege due to double free. This could lead to local escalation of privilege if a malicious …

Sep 7, 2026
CVE-2026-20509
6.7 MEDIUM

In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege …

Sep 7, 2026
CVE-2026-20508
6.7 MEDIUM

In Power HAL, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious …

Sep 7, 2026
CVE-2026-20507
6.7 MEDIUM

In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a …

Sep 7, 2026
CVE-2026-20506
6.7 MEDIUM

In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a …

Sep 7, 2026
CVE-2026-20504
5.3 MEDIUM

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE …

Sep 7, 2026
CVE-2026-20503
5.3 MEDIUM

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE …

Sep 7, 2026
CVE-2026-20500
5.5 MEDIUM

In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges …

Sep 7, 2026
CVE-2026-86238
4.3 MEDIUM

A vulnerability was determined in projectworlds Online Examination System 1.0. The affected element is an unknown function of the file feedback.php of the component Feedback …

Sep 7, 2026
CVE-2026-86237
5.3 MEDIUM

A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20. Impacted is the function test_default_model of the file sdk/src/openagents/sdk/transports/http.py. Performing a manipulation of the argument …

Sep 7, 2026
CVE-2026-86236
6.3 MEDIUM

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/pro_transac.php?action=add. Such manipulation of …

Sep 7, 2026
CVE-2026-86235
6.3 MEDIUM

A flaw has been found in itsourcecode Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/pos_transac.php?action=add. This manipulation of the …

Sep 7, 2026
CVE-2026-86234
6.3 MEDIUM

A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/cust_transac.php?action=add. The manipulation of the argument …

Sep 7, 2026
CVE-2026-86233
6.3 MEDIUM

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/us_del.php?type=user. …

Sep 7, 2026
CVE-2026-86232
6.3 MEDIUM

A weakness has been identified in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_del.php?type=supplier. Executing …

Sep 6, 2026
CVE-2026-86228
4.3 MEDIUM

A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelController.java. Such manipulation of the …

Sep 6, 2026
CVE-2026-83534
6.4 MEDIUM

PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue …

Sep 6, 2026
CVE-2026-19634
6.4 MEDIUM

PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If …

Sep 6, 2026
CVE-2026-86217
5.3 MEDIUM

A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component …

Sep 6, 2026
CVE-2026-86216
4.3 MEDIUM

A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an unknown function of the file /ht/details.php. The …

Sep 6, 2026
CVE-2026-86215
4.3 MEDIUM

A vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown function of the file Front-end/server.php of the component Logout Handler. Such manipulation …

Sep 6, 2026
CVE-2026-86258
5.9 MEDIUM

nbviewer through 1.0.1 contains a path traversal vulnerability in LocalFileHandler.can_show() that uses string-prefix comparison instead of proper path validation. Attackers can read files from sibling …

Sep 6, 2026
CVE-2026-86257
5.4 MEDIUM

wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. …

Sep 6, 2026
CVE-2026-86256
5.4 MEDIUM

wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). After a trainer enters impersonation mode, the view …

Sep 6, 2026
CVE-2026-86255
6.5 MEDIUM

wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can …

Sep 6, 2026
CVE-2026-86254
6.8 MEDIUM

wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym-scope check using raw integer comparison instead of …

Sep 6, 2026
CVE-2026-86253
5.9 MEDIUM

h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments, event.url.pathname is not normalized, so percent-encoded dot segments (%2e%2e) …

Sep 6, 2026
CVE-2026-86252
5.3 MEDIUM

h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including …

Sep 6, 2026
CVE-2026-86251
5.9 MEDIUM

h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility. A double-decoding flaw allows a request path containing double-encoded dot sequences (e.g. …

Sep 6, 2026
CVE-2026-86212
4.3 MEDIUM

A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. The attack …

Sep 6, 2026
CVE-2026-86205
5.4 MEDIUM

h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Referer header pathname. Attackers …

Sep 6, 2026
CVE-2022-51008
5.3 MEDIUM

PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without sending LoginPacket. Attackers can flood the server …

Sep 6, 2026
CVE-2021-48007
6.5 MEDIUM

PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packets with …

Sep 6, 2026
CVE-2020-37277
6.5 MEDIUM

PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple …

Sep 6, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.