CVE Database

38770+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-61437
7.8 HIGH

PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFlow._resolve_pydantic_class (src/praisonai-agents/praisonaiagents/workflows/workflows.py). When a workflow step uses a string output_pydantic reference, …

Jul 10, 2026
CVE-2026-61434
8.8 HIGH

PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attackers to execute restricted commands via find's built-in -exec, -execdir, …

Jul 10, 2026
CVE-2026-60091
7.2 HIGH

PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/runs endpoint. The webhook_url parameter is validated at request time but …

Jul 10, 2026
CVE-2026-59796
8.1 HIGH

In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks

Jul 10, 2026
CVE-2026-59795
8.1 HIGH

In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible

Jul 10, 2026
CVE-2026-59794
7.3 HIGH

In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data

Jul 10, 2026
CVE-2026-59793
8.8 HIGH

In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration

Jul 10, 2026
CVE-2026-56305
8.3 HIGH

Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords without requiring current password confirmation. …

Jul 10, 2026
CVE-2026-56279
7.5 HIGH

Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RPC function that remains publicly invokable despite intended private access controls. Unauthenticated attackers can …

Jul 10, 2026
CVE-2026-56261
8.6 HIGH

Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without destination …

Jul 10, 2026
CVE-2026-56254
7.0 HIGH

In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can …

Jul 10, 2026
CVE-2026-38059
7.5 HIGH

The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can retrieve sensitive device information including …

Jul 10, 2026
CVE-2026-38057
8.1 HIGH

The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session …

Jul 10, 2026
CVE-2026-29519
8.2 HIGH

Lucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines contain a reflected cross-site scripting vulnerability in URL path parsing that allows …

Jul 10, 2026
CVE-2026-22660
7.2 HIGH

FlaskBB through 2.2.0, fixed in commit a5da9a5, contains a logic flaw vulnerability that allows authenticated administrators to delete all built-in authorization groups by exploiting a …

Jul 10, 2026
CVE-2026-22659
8.1 HIGH

FlaskBB through 2.2.0, fixed in commit acc88cf, contains an authorization bypass vulnerability that allows authenticated moderators to perform unauthorized actions on topics in forums they …

Jul 10, 2026
CVE-2026-54469
8.8 HIGH

Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker with remote access could potentially exploit …

Jul 10, 2026
CVE-2026-56690
8.5 HIGH

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged …

Jul 10, 2026
CVE-2026-56689
7.7 HIGH

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged …

Jul 10, 2026
CVE-2026-40454
7.5 HIGH

Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bounds reads in IoTDB C++ client TsBlock deserializer crash client process on malformed server …

Jul 10, 2026
CVE-2026-40452
7.5 HIGH

Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users. This issue affects Apache IoTDB: …

Jul 10, 2026
CVE-2026-40007
7.5 HIGH

Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap receiver's readLength method calls itself recursively each time it recognises the …

Jul 10, 2026
CVE-2026-40006
7.5 HIGH

Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authentication for Critical Function vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enabled=true, the …

Jul 10, 2026
CVE-2026-13347
7.5 HIGH

The Hide My WP Lite plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 1.3 via the he_wrapper_js and …

Jul 10, 2026
CVE-2026-12685
7.5 HIGH

The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that lets an unauthenticated attacker who supplies a hard-coded, per-build key …

Jul 10, 2026
CVE-2026-15330
7.3 HIGH

A vulnerability was determined in zhayujie CowAgent up to 2.1.1. Impacted is the function _build_image_content/_download_to_data_url of the file agent/tools/vision/vision.py of the component Vision Tool. Executing …

Jul 10, 2026
CVE-2026-15298
7.2 HIGH

The TelSender plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting in all versions up to, and including, 1.14.14. This is due to insufficient input …

Jul 10, 2026
CVE-2026-15293
8.0 HIGH

The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.0. This is due to …

Jul 10, 2026
CVE-2026-15291
7.5 HIGH

The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …

Jul 10, 2026
CVE-2026-15290
7.5 HIGH

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to blind SQL Injection via …

Jul 10, 2026
CVE-2026-15288
7.5 HIGH

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and …

Jul 10, 2026
CVE-2026-54423
8.2 HIGH

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step …

Jul 10, 2026
CVE-2026-15070
8.8 HIGH

The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10.30.32. This …

Jul 10, 2026
CVE-2026-13430
7.2 HIGH

The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.13.1 via the …

Jul 10, 2026
CVE-2026-15319
7.3 HIGH

A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. This affects the function IPAllowlist of the file web/backend/middleware/access_control.go of the component Launcher. …

Jul 10, 2026
CVE-2026-54771
8.1 HIGH

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.3, a Langroid application exposing a chat interface to untrusted users may allow direct …

Jul 10, 2026
CVE-2026-50181
7.1 HIGH

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, Langroid's `ReadFileTool` and `WriteFileTool` appear to treat `curr_dir` as the intended working-directory boundary …

Jul 10, 2026
CVE-2026-12598
8.1 HIGH

The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login addon. This …

Jul 10, 2026
CVE-2026-12597
8.1 HIGH

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability …

Jul 10, 2026
CVE-2026-12595
8.1 HIGH

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability …

Jul 10, 2026
CVE-2026-59858
7.8 HIGH

Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field …

Jul 9, 2026
CVE-2026-59856
7.8 HIGH

Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken …

Jul 9, 2026
CVE-2026-59834
7.5 HIGH

SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST /api/search/fullTextSearchBlock concatenates attacker-controlled paths values into SQL predicates used …

Jul 9, 2026
CVE-2026-59832
7.7 HIGH

SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/server/serve.go joins a single-decoded request path with the …

Jul 9, 2026
CVE-2026-33655
7.7 HIGH

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the default SSRF protection configuration did …

Jul 9, 2026
CVE-2026-58143
8.8 HIGH

Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery vulnerability that allows unauthenticated attackers to modify administrator configuration by tricking a logged-in administrator into …

Jul 9, 2026
CVE-2026-57028
7.3 HIGH

An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion. …

Jul 9, 2026
CVE-2026-57026
7.5 HIGH

An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX …

Jul 9, 2026
CVE-2026-57023
7.5 HIGH

An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and …

Jul 9, 2026
CVE-2026-55604
8.6 HIGH

DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.7.0, the process-global `SessionStore` accepts caller-supplied `session_id` …

Jul 9, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.