CVE Database

32607+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-48697
7.4 HIGH

FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_web_request_secure() function in src/fast_library.cpp creates a boost::asio::ssl::context with tls_client mode …

May 26, 2026
CVE-2026-48690
7.1 HIGH

FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer allocation. In src/packet_storage.hpp, the allocate_buffer() function computes memory_size_in_bytes as 'buffer_size_in_packets …

May 26, 2026
CVE-2026-48126
8.2 HIGH

Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --letsencrypt, which silently turns on --domain at …

May 26, 2026
CVE-2026-45728
7.5 HIGH

Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path instead of a directory, singleFileMode …

May 26, 2026
CVE-2026-44729
8.7 HIGH

Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded files using …

May 26, 2026
CVE-2026-44680
7.6 HIGH

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to @mikro-orm/knex 6.6.14 and @mikro-orm/sql 7.0.14, …

May 26, 2026
CVE-2026-24212
7.5 HIGH

NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to …

May 26, 2026
CVE-2026-24162
7.8 HIGH

NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead …

May 26, 2026
CVE-2026-48692
8.1 HIGH

FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initialized with grpc::InsecureServerCredentials() (src/fastnetmon.cpp line …

May 26, 2026
CVE-2026-48688
7.5 HIGH

FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute decoder. The function decode_mp_reach_ipv6() in src/bgp_protocol.cpp contains a TODO comment …

May 26, 2026
CVE-2026-43935
8.1 HIGH

e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset page allows attackers to manipulate the …

May 26, 2026
CVE-2026-25112
7.8 HIGH

A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack.

May 26, 2026
CVE-2026-9552
7.3 HIGH

A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown code of the component Search API Endpoint. The …

May 26, 2026
CVE-2026-9551
7.3 HIGH

A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of the file ParkingRecord/ExportParkingRecords of the component API Endpoint. …

May 26, 2026
CVE-2026-9550
7.3 HIGH

A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Affected by this issue is some unknown functionality of …

May 26, 2026
CVE-2026-4480
8.5 HIGH

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting …

May 26, 2026
CVE-2026-46368
8.8 HIGH

luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by …

May 26, 2026
CVE-2026-45082
7.6 HIGH

Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability was identified in versions prior to 0.32.0 affecting redirect-following processing components. …

May 26, 2026
CVE-2026-42785
7.2 HIGH

OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary Java/BeanShell code through the /admin/Scripting endpoint. Attackers can submit malicious …

May 26, 2026
CVE-2026-42425
7.2 HIGH

OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to execute arbitrary SQL statements against the application database via the DatabaseQuery …

May 26, 2026
CVE-2026-40034
7.8 HIGH

gix-submodule before 0.82.0 incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only …

May 26, 2026
CVE-2026-40033
8.8 HIGH

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps …

May 26, 2026
CVE-2026-9544
7.3 HIGH

A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by this vulnerability is an unknown functionality of the …

May 26, 2026
CVE-2026-48133
7.5 HIGH

When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway.

May 26, 2026
CVE-2026-48132
8.1 HIGH

The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted …

May 26, 2026
CVE-2026-48131
8.1 HIGH

The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This …

May 26, 2026
CVE-2025-11482
7.5 HIGH

An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in PPT30 Operating System versions before 1.8.0 may be used by …

May 26, 2026
CVE-2026-39661
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Magentech SW Core allows PHP Local File Inclusion. This …

May 26, 2026
CVE-2026-25713
7.8 HIGH

MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability

May 26, 2026
CVE-2026-25104
7.8 HIGH

MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability

May 26, 2026
CVE-2026-8047
7.5 HIGH

The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited out-of-bounds write. An unauthenticated remote attacker can exploit this …

May 26, 2026
CVE-2026-8046
8.1 HIGH

The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this vulnerability to delete other users, including those …

May 26, 2026
CVE-2026-44469
7.8 HIGH

The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU …

May 26, 2026
CVE-2026-44468
7.8 HIGH

The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining …

May 26, 2026
CVE-2026-9496
7.5 HIGH

Versions of the package pacote from 11.2.7 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by …

May 26, 2026
CVE-2026-9495
7.3 HIGH

Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnerable to Access Control Bypass due to the middleware being silently dropped from the …

May 26, 2026
CVE-2026-9528
7.3 HIGH

A vulnerability was identified in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the file /admin/delete_judge.php. Such manipulation of the argument judge_id …

May 26, 2026
CVE-2026-9526
7.3 HIGH

A vulnerability was found in itsourcecode Electronic Judging System 1.0. This vulnerability affects unknown code of the file /admin/edit_team.php. The manipulation of the argument num_id …

May 26, 2026
CVE-2026-9525
7.3 HIGH

A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /admin/edit_judge.php. The manipulation of the argument …

May 26, 2026
CVE-2026-9523
7.3 HIGH

A vulnerability was detected in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 3000WEBV2. Affected by this vulnerability is an unknown functionality of …

May 26, 2026
CVE-2026-9538
7.5 HIGH

Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->read($$data, …

May 26, 2026
CVE-2026-9521
7.3 HIGH

A security vulnerability has been detected in fraillt bitsery up to 5.2.4. Affected is the function loadFromSharedState in the library include/bitsery/ext/std_smart_ptr.h. Such manipulation leads to …

May 26, 2026
CVE-2026-42497
7.5 HIGH

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without …

May 26, 2026
CVE-2026-9517
7.3 HIGH

A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/students/addStudentView of the component Student Management Handler. Executing …

May 26, 2026
CVE-2026-48837
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind SQL Injection. This issue affects …

May 25, 2026
CVE-2026-45438
7.5 HIGH

Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Smart Coupons for WooCommerce: from …

May 25, 2026
CVE-2026-45216
8.8 HIGH

Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects Smart Manager: from n/a through 8.85.0.

May 25, 2026
CVE-2026-45209
7.5 HIGH

Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MyCryptoCheckout: from n/a through 2.161.

May 25, 2026
CVE-2026-39436
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery. This issue affects CformsII: from n/a through 15.1.3.

May 25, 2026
CVE-2026-24937
7.2 HIGH

Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcast Live Video allows Code Injection. This issue affects Broadcast Live Video: from n/a …

May 25, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.