CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-85787
6.5 MEDIUM

An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify …

Sep 4, 2026
CVE-2026-85703
6.5 MEDIUM

A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/backend.py of the …

Sep 4, 2026
CVE-2026-85701
5.3 MEDIUM

A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the file g4f/__init__.py of the component Authentication …

Sep 4, 2026
CVE-2026-77847
6.5 MEDIUM

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitive information …

Sep 4, 2026
CVE-2026-53769
6.5 MEDIUM

Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint …

Sep 4, 2026
CVE-2022-26961
5.4 MEDIUM

Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the name parameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. …

Sep 4, 2026
CVE-2026-85643
4.7 MEDIUM

A flaw has been found in code-projects Online Shopping System 1.0. Impacted is the function mysqli_query of the file admin/adduser.php. Executing a manipulation of the …

Sep 4, 2026
CVE-2026-55513
5.4 MEDIUM

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5.0, the nebula-mgmt Web UI host-creation path ignores …

Sep 4, 2026
CVE-2026-55512
5.3 MEDIUM

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.2.0 to before version 0.5.0, when OIDC is enabled, GET /ui/oidc/login is …

Sep 4, 2026
CVE-2026-85639
5.6 MEDIUM

A security vulnerability has been detected in jofpin trape 2.0. This vulnerability affects unknown code of the file core/user.py of the component Telemetry Endpoint. Such …

Sep 4, 2026
CVE-2026-85637
5.3 MEDIUM

A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affected by this issue is the function join_room of the file core/sockets.py of the component …

Sep 4, 2026
CVE-2026-80115
6.1 MEDIUM

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation and denial-of-service vulnerability in …

Sep 4, 2026
CVE-2026-85769
6.5 MEDIUM

A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's …

Sep 4, 2026
CVE-2026-85636
5.3 MEDIUM

A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerability is an unknown functionality of the file core/stats.py of the component Login Endpoint. …

Sep 4, 2026
CVE-2026-84890
5.9 MEDIUM

undici's decompress interceptor decompresses response bodies according to the untrusted Content-Encoding header. While the number of content-encoding layers is capped, the total decompressed output size …

Sep 4, 2026
CVE-2026-61688
6.5 MEDIUM

SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API request history of any other user's API tokens …

Sep 4, 2026
CVE-2026-61614
5.9 MEDIUM

SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the REST API authenticator accepts bearer tokens via a `?token=` URL query parameter as a …

Sep 4, 2026
CVE-2026-61608
6.8 MEDIUM

SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, `UserInvitation` entities have no expiry timestamp. Invitation links mailed to users remain valid indefinitely, meaning …

Sep 4, 2026
CVE-2026-53760
5.2 MEDIUM

Admidio is an open-source user management solution. In versions 5.0.11 and prior, the modules/plugins.php endpoint handles plugin installation, uninstallation, and update operations via GET requests …

Sep 4, 2026
CVE-2026-53756
4.9 MEDIUM

Emlog is an open source website building system. Prior to version 2.6.16, Emlog CMS Pro contains a blind SQL injection in User_Model::getUserDataByLogin(). The $account parameter …

Sep 4, 2026
CVE-2026-18149
5.9 MEDIUM

undici's retry handler can leave an already-exposed response body pending forever. When a server returns a successful response that declares a Content-Length, sends only part …

Sep 4, 2026
CVE-2026-85024
5.9 MEDIUM

undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream, including its error listener, while that stream …

Sep 4, 2026
CVE-2026-85014
5.9 MEDIUM

undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close handshake. On an unclean …

Sep 4, 2026
CVE-2026-84933
6.5 MEDIUM

undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. …

Sep 4, 2026
CVE-2026-38961
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to …

Sep 4, 2026
CVE-2026-18341
6.3 MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.

Sep 4, 2026
CVE-2026-18078
4.3 MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow.

Sep 4, 2026
CVE-2026-18076
4.3 MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak.

Sep 4, 2026
CVE-2026-18073
4.4 MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of …

Sep 4, 2026
CVE-2026-17631
5.0 MEDIUM

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.

Sep 4, 2026
CVE-2026-17627
4.9 MEDIUM

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper …

Sep 4, 2026
CVE-2026-17622
6.5 MEDIUM

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a …

Sep 4, 2026
CVE-2026-17621
5.4 MEDIUM

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL …

Sep 4, 2026
CVE-2026-17499
4.4 MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in …

Sep 4, 2026
CVE-2026-17483
4.3 MEDIUM

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access …

Sep 4, 2026
CVE-2026-17470
5.3 MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.

Sep 4, 2026
CVE-2026-17469
5.3 MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in …

Sep 4, 2026
CVE-2026-17444
5.3 MEDIUM

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated …

Sep 4, 2026
CVE-2026-17443
5.3 MEDIUM

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated …

Sep 4, 2026
CVE-2026-17442
5.1 MEDIUM

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker …

Sep 4, 2026
CVE-2026-17440
5.5 MEDIUM

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker …

Sep 4, 2026
CVE-2026-17274
5.4 MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds.

Sep 4, 2026
CVE-2026-17273
6.5 MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference.

Sep 4, 2026
CVE-2026-17270
4.3 MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow.

Sep 4, 2026
CVE-2026-17259
4.3 MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow.

Sep 4, 2026
CVE-2026-17255
4.3 MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix …

Sep 4, 2026
CVE-2026-17207
6.5 MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer …

Sep 4, 2026
CVE-2026-17057
6.5 MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing …

Sep 4, 2026
CVE-2026-16941
4.3 MEDIUM

IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization.

Sep 4, 2026
CVE-2026-16892
5.4 MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication during service-name matching.

Sep 4, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.