CVE Database

133951+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-45383

libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a heap buffer overflow (out-of-bounds READ) exists in `decoder_context::decode_slice_unit_WPP()` …

Jul 21, 2026
CVE-2026-45382

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, `decoder_context::decode_slice_unit_tiles` (libde265/decctx.cc:920) reads `pps.CtbAddrRStoTS[ctbAddrRS]` at line 966 where `ctbAddrRS = …

Jul 21, 2026
CVE-2026-44879
7.2 HIGH

A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote attacker to perform command injection on certain CLI …

Jul 21, 2026
CVE-2026-44878
7.2 HIGH

A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the device's filesystem. Successful …

Jul 21, 2026
CVE-2026-30633
7.5 HIGH

Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools.

Jul 21, 2026
CVE-2026-30631
9.8 CRITICAL

An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute arbitrary code via crafted path to `computer_write_file`.

Jul 21, 2026
CVE-2026-16318
5.3 MEDIUM

The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store the peer's transport parameters. When a TLS 1.3 connection …

Jul 21, 2026
CVE-2026-16317
6.5 MEDIUM

Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently discard individual application data records …

Jul 21, 2026
CVE-2026-12139
4.4 MEDIUM

Tanium addressed an information disclosure vulnerability in Connect.

Jul 21, 2026
CVE-2026-11925
2.7 LOW

Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server.

Jul 21, 2026
CVE-2026-65069
4.0 MEDIUM

Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in dsu.h …

Jul 21, 2026
CVE-2026-65068
3.8 LOW

Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sphash.h …

Jul 21, 2026
CVE-2026-65067
3.8 LOW

Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in intern.h …

Jul 21, 2026
CVE-2026-65066
3.8 LOW

Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ring.h …

Jul 21, 2026
CVE-2026-65065
5.5 MEDIUM

Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in roaring.h …

Jul 21, 2026
CVE-2026-65064
3.8 LOW

Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in shm_generic.h …

Jul 21, 2026
CVE-2026-65063
3.8 LOW

Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in radix.h …

Jul 21, 2026
CVE-2026-65062
3.8 LOW

Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sortedset.h …

Jul 21, 2026
CVE-2026-65061
3.8 LOW

Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in reqrep.h …

Jul 21, 2026
CVE-2026-64880
7.1 HIGH

Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized …

Jul 21, 2026
CVE-2026-64879
9.9 CRITICAL

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and …

Jul 21, 2026
CVE-2026-64878
9.9 CRITICAL

Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via …

Jul 21, 2026
CVE-2026-64617
3.8 LOW

Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in pubsub.h …

Jul 21, 2026
CVE-2026-64616

Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ndarray.h …

Jul 21, 2026
CVE-2026-64615
3.3 LOW

Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in graph.h …

Jul 21, 2026
CVE-2026-64614
3.8 LOW

Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in deque.h …

Jul 21, 2026
CVE-2026-64613
6.2 MEDIUM

Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOLLOW. The segment is created in buf_generic.h with open(path, …

Jul 21, 2026
CVE-2026-59147
9.8 CRITICAL

Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find. The attach-time validator dsu_validate_header checks the header …

Jul 21, 2026
CVE-2026-59146
7.8 HIGH

Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sph_walk_cell and sph_alloc_slot. The attach-time validator …

Jul 21, 2026
CVE-2026-59145
9.1 CRITICAL

Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find. The attach-time validator si_validate_header is thorough …

Jul 21, 2026
CVE-2026-59144
9.8 CRITICAL

Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time validator ring_validate_header checks the capacity-overflow and …

Jul 21, 2026
CVE-2026-59143
6.3 MEDIUM

Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offset and cardinality in rb_contains_locked. The attach-time validator rb_validate_header checks the …

Jul 21, 2026
CVE-2026-56852
7.5 HIGH

A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

Jul 21, 2026
CVE-2026-56146
5.4 MEDIUM

Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with …

Jul 21, 2026
CVE-2026-56145
6.5 MEDIUM

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL …

Jul 21, 2026
CVE-2026-56144
5.3 MEDIUM

Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By …

Jul 21, 2026
CVE-2026-50759
7.5 HIGH

An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instance/{instance_id} endpoints with no authentication.

Jul 21, 2026
CVE-2026-50758
8.1 HIGH

Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter

Jul 21, 2026
CVE-2026-50757
7.8 HIGH

Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server

Jul 21, 2026
CVE-2026-50756
7.5 HIGH

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component

Jul 21, 2026
CVE-2026-50755
9.8 CRITICAL

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value

Jul 21, 2026
CVE-2026-49092
4.3 MEDIUM

Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under …

Jul 21, 2026
CVE-2026-47671
5.4 MEDIUM

Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost configserver` used by `nhost dev` …

Jul 21, 2026
CVE-2026-47667
7.5 HIGH

CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field is read as an `unsigned int` from …

Jul 21, 2026
CVE-2026-46600
7.5 HIGH

Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

Jul 21, 2026
CVE-2026-46403
6.3 MEDIUM

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithTypedArguments` as a read-only execution mechanism. The hook saves the …

Jul 21, 2026
CVE-2026-42397
6.5 MEDIUM

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can …

Jul 21, 2026
CVE-2026-30632
7.5 HIGH

Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool.

Jul 21, 2026
CVE-2026-15957
7.5 HIGH

Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust …

Jul 21, 2026
CVE-2026-64877
8.4 HIGH

An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.

Jul 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.