CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-62654
6.8 MEDIUM

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance mode can be activated via a physical key sequence during …

Sep 8, 2026
CVE-2026-62653
6.8 MEDIUM

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The input received over a proprietary communication protocol that is exposed when the …

Sep 8, 2026
CVE-2026-62652
5.3 MEDIUM

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from which debugging symbols have not been removed. …

Sep 8, 2026
CVE-2026-58113
6.1 MEDIUM

A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter …

Sep 8, 2026
CVE-2026-81802
6.5 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions.

Sep 8, 2026
CVE-2026-81792
6.5 MEDIUM

Unauthenticated Privilege Escalation in Product Catalog Enquiry for WooCommerce by MultiVendorX <= 6.1.4 versions.

Sep 8, 2026
CVE-2026-86519
5.3 MEDIUM

A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handler. …

Sep 8, 2026
CVE-2026-86518
6.3 MEDIUM

A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument …

Sep 8, 2026
CVE-2026-86517
6.3 MEDIUM

A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of the file /pages/us_searchfrm.php. Executing a …

Sep 8, 2026
CVE-2026-86516
4.7 MEDIUM

A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC …

Sep 8, 2026
CVE-2026-86515
4.3 MEDIUM

A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such …

Sep 8, 2026
CVE-2026-86514
6.3 MEDIUM

A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This …

Sep 8, 2026
CVE-2026-86513
5.3 MEDIUM

A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/com/github/fge/jackson/jsonpointer/TreePointer.java of the component JSON Pointer …

Sep 8, 2026
CVE-2026-86512
6.3 MEDIUM

A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move Operations. …

Sep 8, 2026
CVE-2026-86511
5.3 MEDIUM

A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal.toPlainString of the file src/main/java/com/github/fge/jackson/JacksonUtils.java. Performing a manipulation results in …

Sep 8, 2026
CVE-2026-76977
4.3 MEDIUM

SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing …

Sep 8, 2026
CVE-2026-76971
6.5 MEDIUM

Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. …

Sep 8, 2026
CVE-2026-76968
6.5 MEDIUM

SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive …

Sep 8, 2026
CVE-2026-76963
4.3 MEDIUM

Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive …

Sep 8, 2026
CVE-2026-76962
4.3 MEDIUM

SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted …

Sep 8, 2026
CVE-2026-76959
4.6 MEDIUM

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges …

Sep 8, 2026
CVE-2026-44766
6.5 MEDIUM

SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database …

Sep 8, 2026
CVE-2026-86436
5.4 MEDIUM

Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files. …

Sep 7, 2026
CVE-2026-86506
5.9 MEDIUM

In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data

Sep 7, 2026
CVE-2026-86500
5.5 MEDIUM

In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin

Sep 7, 2026
CVE-2026-86499
4.3 MEDIUM

In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission

Sep 7, 2026
CVE-2026-86497
6.8 MEDIUM

In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials

Sep 7, 2026
CVE-2026-86496
4.3 MEDIUM

In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses

Sep 7, 2026
CVE-2026-86495
6.5 MEDIUM

In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects

Sep 7, 2026
CVE-2026-86493
6.5 MEDIUM

In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards

Sep 7, 2026
CVE-2026-86490
6.5 MEDIUM

In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint

Sep 7, 2026
CVE-2026-86489
6.5 MEDIUM

In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations

Sep 7, 2026
CVE-2026-86488
6.5 MEDIUM

In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches

Sep 7, 2026
CVE-2026-86484
4.6 MEDIUM

In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS

Sep 7, 2026
CVE-2026-86483
5.4 MEDIUM

In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible

Sep 7, 2026
CVE-2026-86481
4.3 MEDIUM

In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons

Sep 7, 2026
CVE-2026-80176
4.7 MEDIUM

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Plaintext Storage of a Password vulnerability. …

Sep 7, 2026
CVE-2026-80167
5.5 MEDIUM

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. …

Sep 7, 2026
CVE-2026-80126
6.5 MEDIUM

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Locking vulnerability. A low privileged …

Sep 7, 2026
CVE-2026-80125
5.9 MEDIUM

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated …

Sep 7, 2026
CVE-2026-80058
5.5 MEDIUM

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Cleartext Storage of Sensitive Information vulnerability. …

Sep 7, 2026
CVE-2026-79975
5.5 MEDIUM

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. A low …

Sep 7, 2026
CVE-2026-86469
5.3 MEDIUM

A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and …

Sep 7, 2026
CVE-2026-86321
5.3 MEDIUM

A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the component URL Validation. …

Sep 7, 2026
CVE-2026-80054
5.5 MEDIUM

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Incorrect Permission Assignment for Critical Resource …

Sep 7, 2026
CVE-2026-79943
4.8 MEDIUM

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Validation of Certificate with Host …

Sep 7, 2026
CVE-2026-79642
5.6 MEDIUM

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated …

Sep 7, 2026
CVE-2026-86319
5.3 MEDIUM

A vulnerability has been found in java-json-tools json-patch up to 1.13. Affected by this vulnerability is the function JsonPatch.apply of the file src/main/java/com/github/fge/jsonpatch/JsonPatch.java of the …

Sep 7, 2026
CVE-2026-86318
5.3 MEDIUM

A flaw has been found in java-json-tools json-patch up to 1.13. Affected is the function JsonMergePatch.fromJson of the file JsonMergePatchDeserializer.java. Executing a manipulation can lead …

Sep 7, 2026
CVE-2026-86317
5.3 MEDIUM

A vulnerability was detected in ggml-org llama.cpp up to 0.4.0. This impacts the function rpc_server::deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component RPC Server. Performing …

Sep 7, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.