CVE Database

11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-53710
10.0 CRITICAL

MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes …

Sep 15, 2026
CVE-2024-58385
9.8 CRITICAL

Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is …

Sep 15, 2026
CVE-2023-54398
9.8 CRITICAL

Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending …

Sep 15, 2026
CVE-2026-91949
9.3 CRITICAL

FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers …

Sep 15, 2026
CVE-2026-55211
9.8 CRITICAL

Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to …

Sep 15, 2026
CVE-2026-37152
9.8 CRITICAL

TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.

Sep 15, 2026
CVE-2026-88617
9.8 CRITICAL

SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint. This allows a remote attacker to escalate privileges.

Sep 15, 2026
CVE-2026-63696
9.1 CRITICAL

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could …

Sep 15, 2026
CVE-2026-63695
9.8 CRITICAL

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading …

Sep 15, 2026
CVE-2026-59971
10.0 CRITICAL

MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct …

Sep 15, 2026
CVE-2026-55158
9.1 CRITICAL

Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1, src/index.ts builds git checkout, git …

Sep 15, 2026
CVE-2026-39919
9.8 CRITICAL

Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying …

Sep 15, 2026
CVE-2026-91998
9.9 CRITICAL

Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access …

Sep 15, 2026
CVE-2026-91995
9.1 CRITICAL

pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. …

Sep 15, 2026
CVE-2026-57148
9.8 CRITICAL

PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the public dev-secret-change-me HS256 signing key when PLATFORM_JWT_SECRET is unset, while the …

Sep 15, 2026
CVE-2026-57147
9.8 CRITICAL

PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production guard …

Sep 15, 2026
CVE-2026-57141
9.8 CRITICAL

PraisonAI is a multi-agent teams system. Prior to 1.7.2, the codeMode tool in src/praisonai-ts/src/tools/builtins/code-mode.ts executes model-generated JavaScript with new Function() and with(sandbox), while a regular-expression …

Sep 15, 2026
CVE-2026-57140
9.4 CRITICAL

PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the 0.0.0.0 default from src/praisonai-ts/src/os/config.ts and registers GET /api/agents and POST …

Sep 15, 2026
CVE-2026-57139
9.8 CRITICAL

PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/server.ts binds without a host restriction and forwards every HTTP POST request to …

Sep 15, 2026
CVE-2026-57138
9.9 CRITICAL

PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes untrusted JavaScript with new Function() inside with(sandbox) and relies on a …

Sep 15, 2026
CVE-2026-62379
9.8 CRITICAL

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value …

Sep 15, 2026
CVE-2026-90711
9.1 CRITICAL

proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 …

Sep 15, 2026
CVE-2026-91003
9.1 CRITICAL

A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. …

Sep 15, 2026
CVE-2026-91001
9.9 CRITICAL

A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing …

Sep 15, 2026
CVE-2026-90847
9.1 CRITICAL

A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. …

Sep 15, 2026
CVE-2026-12944
9.6 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components …

Sep 14, 2026
CVE-2026-86881
9.1 CRITICAL

A certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, …

Sep 14, 2026
CVE-2026-84625
9.1 CRITICAL

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27, …

Sep 14, 2026
CVE-2026-84609
9.8 CRITICAL

A permissions issue was addressed with improved path validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia …

Sep 14, 2026
CVE-2026-84561
9.8 CRITICAL

A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, …

Sep 14, 2026
CVE-2026-84520
9.8 CRITICAL

A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Golden Gate 27. A local attacker may be able to …

Sep 14, 2026
CVE-2026-65414
9.8 CRITICAL

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, …

Sep 14, 2026
CVE-2026-65381
10.0 CRITICAL

A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS …

Sep 14, 2026
CVE-2026-53713
9.1 CRITICAL

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in …

Sep 14, 2026
CVE-2026-43790
9.1 CRITICAL

The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote …

Sep 14, 2026
CVE-2026-55209
9.8 CRITICAL

resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata insufficiently validates numeric fields, grid dimensions, keyword …

Sep 14, 2026
CVE-2026-54334
9.8 CRITICAL

UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, ReadCLen() in uefi_firmware/compression/Tiano/Decompress.c reads Number …

Sep 14, 2026
CVE-2026-54333
9.8 CRITICAL

UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, MakeTable() in uefi_firmware/compression/Tiano/Decompress.c does not …

Sep 14, 2026
CVE-2026-50006
9.1 CRITICAL

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to …

Sep 14, 2026
CVE-2026-16338
9.9 CRITICAL

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper …

Sep 14, 2026
CVE-2026-59178
9.8 CRITICAL

ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME_USERNAME` …

Sep 14, 2026
CVE-2026-90945
9.8 CRITICAL

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge …

Sep 14, 2026
CVE-2026-90942
9.6 CRITICAL

Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers …

Sep 14, 2026
CVE-2026-76461
9.8 CRITICAL KEV

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands …

Sep 14, 2026
CVE-2026-76443
9.8 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering …

Sep 14, 2026
CVE-2026-76441
9.8 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering …

Sep 14, 2026
CVE-2026-76440
9.8 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering …

Sep 14, 2026
CVE-2026-20353
9.8 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering …

Sep 14, 2026
CVE-2026-61534
9.1 CRITICAL

Yayson is a library for serializing and reading JSON API data in JavaScript. Prior to 4.3.0, Store and LegacyStore use attacker-controlled JSON:API type, id, and …

Sep 14, 2026
CVE-2026-57145
9.1 CRITICAL

PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-controlled filepath parameter directly to open for reading and writing without traversal rejection, …

Sep 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.