CVE Database

116527+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-6500

Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data. This issue affects OpenConcerto: 1.7.5.

May 4, 2026
CVE-2026-33523
6.5 MEDIUM

HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. …

May 4, 2026
CVE-2026-33007
5.3 MEDIUM

A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in …

May 4, 2026
CVE-2026-33006
4.8 MEDIUM

A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade …

May 4, 2026
CVE-2026-29169
7.5 HIGH

A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock …

May 4, 2026
CVE-2026-23918
8.8 HIGH

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to …

May 4, 2026
CVE-2025-70072
6.5 MEDIUM

An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp, FBXConverter::ConvertMeshMultiMaterial() components

May 4, 2026
CVE-2025-70070
6.5 MEDIUM

An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXMeshGeometry.cpp, MeshGeometry::MeshGeometry()

May 4, 2026
CVE-2025-13605

3onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to execute arbitrary shell commands in the context of the root user by …

May 4, 2026
CVE-2026-6499

Incorrect Permission Assignment for Critical Resource vulnerability in ILM Informatique OpenConcerto allows Replace Binaries. This issue affects OpenConcerto: 1.7.5.

May 4, 2026
CVE-2026-6266
8.3 HIGH

A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external Identity Provider (IDP) identity to …

May 4, 2026
CVE-2026-34032
5.3 MEDIUM

Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version …

May 4, 2026
CVE-2026-33857
5.3 MEDIUM

Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, …

May 4, 2026
CVE-2026-31205
5.7 MEDIUM

Cross Site Scripting vulnerability in Pluck CMS before v.4.7.21dev allows a remote attacker to escalate privileges via the editpage.php and the sanitizePageContent function

May 4, 2026
CVE-2025-70069
7.5 HIGH

An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp and ConvertMeshMultiMaterial() method

May 4, 2026
CVE-2025-70067
9.8 CRITICAL

Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, where a property key string from …

May 4, 2026
CVE-2025-58074
8.8 HIGH

A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during the installation …

May 4, 2026
CVE-2026-7482
9.1 CRITICAL

Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied GGUF file in which the …

May 4, 2026
CVE-2026-34059
7.5 HIGH

Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes …

May 4, 2026
CVE-2026-24072
8.8 HIGH

An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of …

May 4, 2026
CVE-2026-3120
7.2 HIGH

Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and Industry Limited Company SambaBox allows OS Command Injection. This …

May 4, 2026
CVE-2026-7750
8.8 HIGH

A vulnerability was detected in Totolink N300RH 3.2.4-B20220812. This vulnerability affects the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The …

May 4, 2026
CVE-2026-7749
8.8 HIGH

A security vulnerability has been detected in Totolink N300RH 3.2.4-B20220812. This affects the function setWanConfig of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. …

May 4, 2026
CVE-2026-7748
8.8 HIGH

A weakness has been identified in Totolink N300RH 3.2.4-B20220812. Affected by this issue is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component POST …

May 4, 2026
CVE-2026-33846
7.5 HIGH

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are …

May 4, 2026
CVE-2026-7747
9.8 CRITICAL

A security flaw has been discovered in Totolink N300RH 3.2.4-B20220812. Affected by this vulnerability is the function loginauth of the file /cgi-bin/cstecgi.cgi of the component …

May 4, 2026
CVE-2026-7746
6.3 MEDIUM

A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknown function of the file /product_expiry/edit-admin.php. Such manipulation of the …

May 4, 2026
CVE-2026-7745
6.3 MEDIUM

A vulnerability was determined in CodeAstro Online Classroom 1.0. This impacts an unknown function of the file /OnlineClassroom/facultydetails. This manipulation of the argument deleteid causes …

May 4, 2026
CVE-2025-14320
9.8 CRITICAL

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management and Information Services Trade Limited Company Online Support Application allows Reflected …

May 4, 2026
CVE-2026-7744
6.3 MEDIUM

A vulnerability was found in CodeAstro Online Classroom 1.0. This affects an unknown function of the file /OnlineClassroom/addnewstudent. The manipulation of the argument fname results …

May 4, 2026
CVE-2026-7743
6.3 MEDIUM

A vulnerability has been found in CodeAstro Online Classroom 1.0. The impacted element is an unknown function of the file /OnlineClassroom/studentdetails. The manipulation of the …

May 4, 2026
CVE-2026-7742
6.3 MEDIUM

A flaw has been found in CodeAstro Online Classroom 1.0. The affected element is an unknown function of the file /OnlineClassroom/facultylogin. Executing a manipulation of …

May 4, 2026
CVE-2026-7741
6.3 MEDIUM

A vulnerability was detected in CodeAstro Online Classroom 1.0. Impacted is an unknown function of the file /OnlineClassroom/studentlogin. Performing a manipulation of the argument sid …

May 4, 2026
CVE-2026-7740
3.3 LOW

A security vulnerability has been detected in justdan96 tsMuxer up to 2.7.0. This issue affects the function VvcVpsUnit::setFPS of the file tsMuxer/vvc.cpp. Such manipulation of …

May 4, 2026
CVE-2026-7739
3.3 LOW

A weakness has been identified in justdan96 tsMuxer up to 2.7.0. This vulnerability affects the function HevcVpsUnit::setFPS of the file /AFLplusplus/tsMuxer_prev/tsMuxer/hevc.cpp. This manipulation of the …

May 4, 2026
CVE-2026-7738
6.3 MEDIUM

A security flaw has been discovered in puchunjie doc-tools-mcp 1.0.18. This affects the function create_document/open_document of the file src/mcp-server.ts of the component MCP Interface. The …

May 4, 2026
CVE-2026-7737
5.3 MEDIUM

A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.ParseBody/BMPStatisticsReport.ParseBody of the file pkg/packet/bmp/bmp.go of the component …

May 4, 2026
CVE-2026-7736
7.3 HIGH

A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a manipulation …

May 4, 2026
CVE-2026-5335
5.3 MEDIUM

The Magic Export & Import WordPress plugin before 1.2.0 stores exported CSV files at a publicly accessible location, making it possible for any visitors to …

May 4, 2026
CVE-2026-43864
2.5 LOW

mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.

May 4, 2026
CVE-2026-43863
3.7 LOW

mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.

May 4, 2026
CVE-2026-43862
3.7 LOW

In mutt before 2.3.2, the imap_auth_gss security level is mishandled.

May 4, 2026
CVE-2026-43861
3.7 LOW

mutt before 2.3.2 does not check for '\0' in url_pct_decode.

May 4, 2026
CVE-2026-43860
3.7 LOW

mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.

May 4, 2026
CVE-2026-43859
3.7 LOW

mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.

May 4, 2026
CVE-2026-29200

A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows a tenant administrator …

May 4, 2026
CVE-2026-29199
8.1 HIGH

phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabled, the servers hostname may …

May 4, 2026
CVE-2026-20451
6.7 MEDIUM

In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious …

May 4, 2026
CVE-2026-20450
6.5 MEDIUM

In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has …

May 4, 2026
CVE-2026-20449
6.5 MEDIUM

In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE …

May 4, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.