CVE Database

116527+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-34996

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not …

Apr 30, 2026
CVE-2026-34995

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not …

Apr 30, 2026
CVE-2026-34994

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not …

Apr 30, 2026
CVE-2025-51850

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not …

Apr 30, 2026
CVE-2025-51849

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not …

Apr 30, 2026
CVE-2025-51847

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not …

Apr 30, 2026
CVE-2025-14543
9.1 CRITICAL

Improper Restriction of XML External Entity Reference vulnerability in Connext Professional (Core Libraries) allows Serialized Data External Linking.This issue affects Connext Professional: from 7.4.0 before …

Apr 30, 2026
CVE-2026-7500
5.4 MEDIUM

When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — …

Apr 30, 2026
CVE-2026-36959
7.5 HIGH

U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. This allows an attacker on the local network …

Apr 30, 2026
CVE-2026-36958
7.5 HIGH

A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concurrent HTTP requests to random or non-existent endpoints …

Apr 30, 2026
CVE-2026-36957
7.5 HIGH

Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI handler. By initiating …

Apr 30, 2026
CVE-2026-36956
8.8 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireless router V1.0.0. The router fails to …

Apr 30, 2026
CVE-2026-7246
7.2 HIGH

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged …

Apr 30, 2026
CVE-2026-7163
6.1 MEDIUM

A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped …

Apr 30, 2026
CVE-2026-2892
7.5 HIGH

The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including, 3.1.4. This is due to the …

Apr 30, 2026
CVE-2026-7402
8.1 HIGH

Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

Apr 30, 2026
CVE-2026-7399
8.1 HIGH

Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege Abuse. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

Apr 30, 2026
CVE-2026-7382
6.5 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare Software Development Inc. PDKS allows …

Apr 30, 2026
CVE-2025-14576
7.8 HIGH

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt …

Apr 30, 2026
CVE-2024-13971
7.5 HIGH

Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read access to …

Apr 30, 2026
CVE-2026-5080
5.9 MEDIUM

Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely. The session id is generated from summing the character codepoints of the absolute pathname with …

Apr 30, 2026
CVE-2026-41882
7.4 HIGH

In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server

Apr 30, 2026
CVE-2026-31693
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In several places in the code, we have a …

Apr 30, 2026
CVE-2026-1493
5.4 MEDIUM

LEX Baza Dokumentów is vulnerable to DOM-based XSS in "em" cookie parameter. The application unsafely processes the parameter on the client side, allowing an attacker …

Apr 30, 2026
CVE-2026-31787
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: fix double free via VMA splitting privcmd_vm_ops defines .close (privcmd_close), but neither .may_split nor …

Apr 30, 2026
CVE-2026-31786
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Buffer overflow in drivers/xen/sys-hypervisor.c The build id returned by HYPERVISOR_xen_version(XENVER_build_id) is neither NUL terminated nor …

Apr 30, 2026
CVE-2026-31692
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rtnetlink: add missing netlink_ns_capable() check for peer netns rtnl_newlink() lacks a CAP_NET_ADMIN capability check on …

Apr 30, 2026
CVE-2026-6498
5.3 MEDIUM

The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in versions up to, and including, 2.7.16 …

Apr 30, 2026
CVE-2026-42800
7.4 HIGH

NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation. This vulnerability is associated with program files sip/utils/src/sipuri.c.

Apr 30, 2026
CVE-2026-41016
5.9 MEDIUM

Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performed on the TLS upgrade. A man-in-the-middle between …

Apr 30, 2026
CVE-2026-42799
7.4 HIGH

Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects Kestrel: before 2026/02/10.

Apr 30, 2026
CVE-2026-42512
8.1 HIGH

As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. The code which expands the …

Apr 30, 2026
CVE-2026-39457
7.8 HIGH

When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whether the provided socket descriptor …

Apr 30, 2026
CVE-2026-35547
8.1 HIGH

When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of validation allows a malicious program to …

Apr 30, 2026
CVE-2026-22070
7.1 HIGH

ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.

Apr 30, 2026
CVE-2026-7164
7.5 HIGH

Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a stack overflow and panic. Remote attackers can craft packets …

Apr 30, 2026
CVE-2026-7270
7.8 HIGH

An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2) argument buffers. The …

Apr 30, 2026
CVE-2026-6870
5.5 MEDIUM

GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6869
5.5 MEDIUM

WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6867
5.5 MEDIUM

SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6538
5.5 MEDIUM

BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6537
5.5 MEDIUM

ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6536
5.5 MEDIUM

DLMS/COSEM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4

Apr 30, 2026
CVE-2026-6535
5.5 MEDIUM

Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6534
5.5 MEDIUM

USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6533
5.5 MEDIUM

Dissection engine LZ77 decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6532
5.5 MEDIUM

Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6531
5.5 MEDIUM

SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6530
5.5 MEDIUM

DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6529
5.5 MEDIUM

iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.