CVE Database

116527+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-71254
7.5 HIGH

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

May 6, 2026
CVE-2025-71253
7.5 HIGH

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

May 6, 2026
CVE-2025-71252
7.5 HIGH

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

May 6, 2026
CVE-2025-71251
7.5 HIGH

In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution …

May 6, 2026
CVE-2026-44405
3.4 LOW

In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.

May 6, 2026
CVE-2026-40934
6.8 MEDIUM

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a …

May 5, 2026
CVE-2026-40110
7.3 HIGH

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins …

May 5, 2026
CVE-2026-40075
7.5 HIGH

OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the `/openmrs/moduleResources/{moduleid}` endpoint is …

May 5, 2026
CVE-2026-28780
9.8 CRITICAL

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious …

May 5, 2026
CVE-2026-41950
6.5 MEDIUM

Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within …

May 5, 2026
CVE-2026-40068
8.8 HIGH

In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker …

May 5, 2026
CVE-2026-39852
8.2 HIGH

Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between …

May 5, 2026
CVE-2026-39849
8.8 HIGH

Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1, the `dns.interface` configuration field in Pi-hole FTL …

May 5, 2026
CVE-2026-39402
6.5 MEDIUM

lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_line() function that allows an …

May 5, 2026
CVE-2026-39383
7.2 HIGH

Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access can force the server to make outbound HTTP POST …

May 5, 2026
CVE-2026-35579
9.8 CRITICAL

CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations incorrectly handle TSIG authentication. …

May 5, 2026
CVE-2026-35527
5.0 MEDIUM

Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues an outbound HEAD request to …

May 5, 2026
CVE-2026-7857
7.2 HIGH

A vulnerability has been found in D-Link DI-8100 16.07.26A1. This vulnerability affects the function sprintf of the file /user_group.asp of the component CGI Handler. The …

May 5, 2026
CVE-2026-7856
7.2 HIGH

A flaw has been found in D-Link DI-8100 16.07.26A1. This affects an unknown part of the file /url_member.asp of the component Web Management Interface. Executing …

May 5, 2026
CVE-2026-44331
8.1 HIGH

In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c allows a remote attacker to inject arbitrary SQL commands via a …

May 5, 2026
CVE-2026-40331

Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 through 7.4.9, and 7.5.0 through 7.5.2, the …

May 5, 2026
CVE-2026-40330

Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 through 7.4.9, and 7.5.0 through 7.5.2, a …

May 5, 2026
CVE-2026-40329

Masa CMS is an open source content management system. In versions 7.5.2 and earlier, a SQL injection vulnerability exists in the beanFeed.cfc component within the …

May 5, 2026
CVE-2026-40280
7.5 HIGH

Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the default private-IP deny-lists for the --webhook-deny-list and --api-download-from-deny-list flags use a case-sensitive …

May 5, 2026
CVE-2026-38947
6.1 MEDIUM

FluentCMS 1.2.3 is vulnerable to Cross Site Scripting (XSS) in TextHTML plugin.

May 5, 2026
CVE-2026-35453
5.4 MEDIUM

PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.3 and earlier, 2.0.0 through 2.1.15, 2.2.0 through 2.4.4, 3.3.0 through 3.10.4, and …

May 5, 2026
CVE-2026-35397
8.8 HIGH

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated …

May 5, 2026
CVE-2026-34596
7.0 HIGH

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a Time-of-Check-to-Time-of-Use (TOCTOU) race condition exists during addon installation. When …

May 5, 2026
CVE-2026-34527
5.3 MEDIUM

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, SbieIniServer::HashPassword converts a SHA-1 digest to hexadecimal incorrectly. The high …

May 5, 2026
CVE-2026-34464
8.8 HIGH

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipeServer::OpenHandler copies the server field from NAMED_PIPE_OPEN_REQ into a fixed …

May 5, 2026
CVE-2026-34462
7.8 HIGH

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several ProcessServer handlers (KillAllHandler, SuspendAllHandler, and RunSandboxedHandler) copy a WCHAR …

May 5, 2026
CVE-2026-34461
7.8 HIGH

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieIniServer RunSbieCtrl handler contains a stack buffer overflow. The …

May 5, 2026
CVE-2026-34459
8.8 HIGH

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieSvc proxy service's GetRawInputDeviceInfoSlave handler contains two vulnerabilities that …

May 5, 2026
CVE-2026-34458
8.8 HIGH

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI injection vulnerability allows any standard local user to …

May 5, 2026
CVE-2026-34084
9.8 CRITICAL

PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and …

May 5, 2026
CVE-2026-33975

Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-server's SecureHttpClientService can be bypassed using …

May 5, 2026
CVE-2026-33489
7.5 HIGH

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL stanza when both a …

May 5, 2026
CVE-2026-33420
5.3 MEDIUM

Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details endpoint (GET /api/organizations/{org_id}/collections/details) is missing the has_full_access() authorization check that …

May 5, 2026
CVE-2026-33324
8.8 HIGH

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to …

May 5, 2026
CVE-2026-33190
7.5 HIGH

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-DNS transports (DoT, DoH, DoH3, …

May 5, 2026
CVE-2026-32936
7.5 HIGH

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter values and …

May 5, 2026
CVE-2026-32934
7.5 HIGH

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven into unbounded goroutine and memory …

May 5, 2026
CVE-2026-32699

FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fails to validate the nick parameter during a POST …

May 5, 2026
CVE-2026-32603
6.5 MEDIUM

Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial of service vulnerability exists in the Sandboxie …

May 5, 2026
CVE-2026-31893

Tunnelblick is an open source graphic user interface for OpenVPN on macOS. In versions 3.3beta26 through 9.0beta01, any local user can read arbitrary root-owned files …

May 5, 2026
CVE-2024-52911
7.5 HIGH

Bitcoin Core through 28.x has a security issue, the details of which are not disclosed. The earliest affected version is 0.14.

May 5, 2026
CVE-2026-7855
8.8 HIGH

A vulnerability was detected in D-Link DI-8100 16.07.26A1. Affected by this issue is the function tggl_asp of the file /tggl.asp of the component HTTP Request …

May 5, 2026
CVE-2026-7854
9.8 CRITICAL

A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function url_rule_asp of the file /url_rule.asp of the component …

May 5, 2026
CVE-2026-42997
7.7 HIGH

An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a …

May 5, 2026
CVE-2026-38428
9.8 CRITICAL

Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL …

May 5, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.