CVE Database

45217+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-80161
7.8 HIGH

Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context …

Sep 8, 2026
CVE-2026-79909
7.8 HIGH

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Sep 8, 2026
CVE-2026-79908
7.8 HIGH

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Sep 8, 2026
CVE-2026-79907
7.8 HIGH

Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Sep 8, 2026
CVE-2026-77827
7.1 HIGH

Maono Link 3.8.13 MaonoAiServices Windows service allows local privilege escalation for a standard user account via improper write privileges in 'C:\ProgramData\Maono'. Fixed in 4.0.80.

Sep 8, 2026
CVE-2026-30754
8.8 HIGH

A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP encoding process. In the nal_send function in libavformat/rtpenc_h264_hevc.c, a negative size parameter (size=-3) is …

Sep 8, 2026
CVE-2026-19651
7.4 HIGH

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due …

Sep 8, 2026
CVE-2026-86810
7.3 HIGH

A vulnerability was detected in Open-Web-Analytics up to 1.9.1. The impacted element is the function checkCapabilityAndAuthenticateUser of the file Core/Controller.php of the component Controller. Performing …

Sep 8, 2026
CVE-2026-86808
7.3 HIGH

A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation …

Sep 8, 2026
CVE-2026-86806
7.3 HIGH

A weakness has been identified in opengeos GeoLibre up to 2.3.0. Impacted is the function _is_within_roots. This manipulation causes server-side request forgery. The attack can …

Sep 8, 2026
CVE-2026-84942
8.7 HIGH

Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript …

Sep 8, 2026
CVE-2026-82007
7.8 HIGH

Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. …

Sep 8, 2026
CVE-2026-82006
7.8 HIGH

Photoshop Desktop is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Sep 8, 2026
CVE-2026-82005
7.8 HIGH

Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Sep 8, 2026
CVE-2026-78834
8.8 HIGH

A code execution vulnerability exists in CMSimple 5.22 in the CoAuthors plugin. An authenticated low-privileged user who can modify page content and provide controlled imported …

Sep 8, 2026
CVE-2026-78627
7.3 HIGH

The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in …

Sep 8, 2026
CVE-2026-78626
8.1 HIGH

The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an …

Sep 8, 2026
CVE-2026-78623
7.7 HIGH

The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode datastore configuration. The unsanitized values …

Sep 8, 2026
CVE-2026-78574
7.5 HIGH

The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is …

Sep 8, 2026
CVE-2026-76199
8.6 HIGH

Photoshop Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. …

Sep 8, 2026
CVE-2026-76190
8.6 HIGH

ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the …

Sep 8, 2026
CVE-2026-75999
8.4 HIGH

ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged …

Sep 8, 2026
CVE-2026-75998
7.5 HIGH

ColdFusion is affected by an Improper Access Control vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access …

Sep 8, 2026
CVE-2026-75993
8.5 HIGH

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially …

Sep 8, 2026
CVE-2026-75992
7.8 HIGH

Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this …

Sep 8, 2026
CVE-2026-75991
8.6 HIGH

Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker …

Sep 8, 2026
CVE-2026-75990
8.6 HIGH

Illustrator is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could …

Sep 8, 2026
CVE-2026-75863
7.8 HIGH

Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. …

Sep 8, 2026
CVE-2026-75862
7.8 HIGH

Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. …

Sep 8, 2026
CVE-2026-75771
7.8 HIGH

Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. …

Sep 8, 2026
CVE-2026-75631
7.8 HIGH

Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Sep 8, 2026
CVE-2026-28659
7.8 HIGH

In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. This could lead to local escalation …

Sep 8, 2026
CVE-2026-86716
7.3 HIGH

A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skip_spaces_and_comments of the file src/mjs_tok.c. Executing a manipulation can lead to …

Sep 8, 2026
CVE-2026-82537
8.8 HIGH

Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability that allows attackers to execute denied shell commands by exploiting a word-boundary mismatch in comment handling between …

Sep 8, 2026
CVE-2026-82536
8.8 HIGH

Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command parsing logic that allows attackers to execute denied shell commands by exploiting the …

Sep 8, 2026
CVE-2026-77774
8.6 HIGH

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass …

Sep 8, 2026
CVE-2026-77111
8.7 HIGH

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this …

Sep 8, 2026
CVE-2026-77110
7.6 HIGH

Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature …

Sep 8, 2026
CVE-2026-77109
8.6 HIGH

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access …

Sep 8, 2026
CVE-2026-77108
7.5 HIGH

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access …

Sep 8, 2026
CVE-2026-76202
8.2 HIGH

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access …

Sep 8, 2026
CVE-2026-69646
8.3 HIGH

Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.

Sep 8, 2026
CVE-2026-66307
7.5 HIGH

Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-66305
7.1 HIGH

Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.

Sep 8, 2026
CVE-2026-66304
7.5 HIGH

Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-58941
7.8 HIGH

In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation. This could lead to local escalation of …

Sep 8, 2026
CVE-2026-58874
7.8 HIGH

In multiple functions of SmsController.java, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of …

Sep 8, 2026
CVE-2026-58848
7.0 HIGH

In multiple functions of alloc.c, there is a possible unauthorized read/write access due to a race condition. This could lead to local escalation of privilege …

Sep 8, 2026
CVE-2026-58846
7.8 HIGH

In kvm_iommu_map_sg of iommu.c, there is a possible use after free due to a missing permission check. This could lead to local escalation of privilege …

Sep 8, 2026
CVE-2026-58839
7.8 HIGH

In forEachLine of MountRegistry.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local escalation of privilege …

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.