CVE Database

9856+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-46994
9.8 CRITICAL

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and …

Jul 21, 2026
CVE-2026-46989
9.1 CRITICAL

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.5 and 24.1. …

Jul 21, 2026
CVE-2026-46983
9.8 CRITICAL

Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 16.0.3. Easily exploitable …

Jul 21, 2026
CVE-2026-46982
9.8 CRITICAL

Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 14.1.3.2. Easily exploitable …

Jul 21, 2026
CVE-2026-46924
9.8 CRITICAL

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP …

Jul 21, 2026
CVE-2026-46876
9.8 CRITICAL

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle …

Jul 21, 2026
CVE-2026-35290
9.8 CRITICAL

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP …

Jul 21, 2026
CVE-2026-65057
9.3 CRITICAL

Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host …

Jul 21, 2026
CVE-2026-63764
9.3 CRITICAL

lmdeploy's OpenAI-compatible API server contains a server-side request forgery vulnerability that allows unauthenticated attackers to access internal services and cloud metadata endpoints by supplying a …

Jul 21, 2026
CVE-2026-64879
9.9 CRITICAL

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and …

Jul 21, 2026
CVE-2026-64878
9.9 CRITICAL

Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via …

Jul 21, 2026
CVE-2016-20096
9.8 CRITICAL

Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the …

Jul 21, 2026
CVE-2026-47416
9.6 CRITICAL

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/members/{user_id}` …

Jul 21, 2026
CVE-2026-47413
9.6 CRITICAL

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST …

Jul 21, 2026
CVE-2026-47410
9.8 CRITICAL

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing …

Jul 21, 2026
CVE-2026-64825
9.3 CRITICAL

Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem …

Jul 21, 2026
CVE-2026-47396
9.8 CRITICAL

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent control API without authentication when `CALL_SERVER_TOKEN` is not …

Jul 21, 2026
CVE-2026-47393
9.8 CRITICAL

PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.generate_api_server_code`) that emits a Flask API server with authentication disabled by …

Jul 21, 2026
CVE-2026-47392
9.9 CRITICAL

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` in `praisonaiagents/tools/python_tools.py` (v1.6.37, subprocess sandbox mode) …

Jul 21, 2026
CVE-2026-47391
9.8 CRITICAL

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC endpoint and registers a `calculate(expression)` …

Jul 21, 2026
CVE-2026-28321
9.1 CRITICAL

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate …

Jul 21, 2026
CVE-2026-28317
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The …

Jul 21, 2026
CVE-2026-28316
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability …

Jul 21, 2026
CVE-2026-28314
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower …

Jul 21, 2026
CVE-2026-28313
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact …

Jul 21, 2026
CVE-2026-28312
9.1 CRITICAL

SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The …

Jul 21, 2026
CVE-2026-28310
9.1 CRITICAL

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. …

Jul 21, 2026
CVE-2026-28309
9.1 CRITICAL

SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in …

Jul 21, 2026
CVE-2026-28308
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The …

Jul 21, 2026
CVE-2026-28307
9.1 CRITICAL

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is …

Jul 21, 2026
CVE-2026-28306
9.1 CRITICAL

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is …

Jul 21, 2026
CVE-2026-28305
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with …

Jul 21, 2026
CVE-2026-28304
9.1 CRITICAL

SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact …

Jul 21, 2026
CVE-2026-28302
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This …

Jul 21, 2026
CVE-2026-65049
9.3 CRITICAL

Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of …

Jul 21, 2026
CVE-2026-65048
9.3 CRITICAL

Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary …

Jul 21, 2026
CVE-2026-16412
9.8 CRITICAL

Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with …

Jul 21, 2026
CVE-2026-16411
9.8 CRITICAL

Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of …

Jul 21, 2026
CVE-2026-16408
9.8 CRITICAL

Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16406
9.1 CRITICAL

Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16395
9.8 CRITICAL

Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16394
9.1 CRITICAL

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16361
9.8 CRITICAL

Memory safety bugs present in Firefox ESR 115.37 and Firefox ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that …

Jul 21, 2026
CVE-2026-16359
9.1 CRITICAL

Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-65008
9.8 CRITICAL

Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to …

Jul 21, 2026
CVE-2026-65007
9.6 CRITICAL

The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks before the …

Jul 21, 2026
CVE-2026-1617
9.8 CRITICAL

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama allows SQL Injection. This …

Jul 21, 2026
CVE-2026-64606
9.8 CRITICAL

Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue …

Jul 21, 2026
CVE-2026-64609
9.1 CRITICAL

Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy …

Jul 21, 2026
CVE-2026-64608
9.8 CRITICAL

Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate …

Jul 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.