CVE Database

5195+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-28638
3.3 LOW

In multiple functions of XmpDataParser.java, there is a possible improper data sanitization due to a logic error in the code. This could lead to local …

Sep 8, 2026
CVE-2026-28630
3.3 LOW

In onCreate of ContactsPickerActivity.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local information disclosure with no additional …

Sep 8, 2026
CVE-2026-28623
3.3 LOW

In writeToParcel of BleRssiRangingCapabilities.java, there is a possible way to obtain the Bluetooth MAC address due to a missing permission check. This could lead to …

Sep 8, 2026
CVE-2026-28622
3.3 LOW

In getQueryBuilderInternal of MediaProvider.java, there is a possible way to retrieve location metadata due to a permissions bypass. This could lead to local information disclosure …

Sep 8, 2026
CVE-2026-28582
3.3 LOW

In onCreate of ConfirmDeviceCredentialActivity.java, there is a possible unauthorized access to and modification of device credentials due to a missing permission check. This could lead …

Sep 8, 2026
CVE-2026-0054
3.3 LOW

In isCallerAllowed of WalletContextualLocationsService.kt, there is a possible way to get wallet information due to a missing permission check. This could lead to local information …

Sep 8, 2026
CVE-2026-9216
3.5 LOW

An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash …

Sep 8, 2026
CVE-2026-86670
3.7 LOW

A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/admin.php of the component Authentication Storage. …

Sep 8, 2026
CVE-2026-69904
3.5 LOW

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-69615
3.5 LOW

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Sep 8, 2026
CVE-2026-48707
3.1 LOW

InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload …

Sep 8, 2026
CVE-2026-84392
2.7 LOW

A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 …

Sep 8, 2026
CVE-2026-84389
3.1 LOW

A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized …

Sep 8, 2026
CVE-2026-82069
2.7 LOW

A security issue in MongoDB Server's query statistics serialization on the router allows users with monitoring privileges to access unredacted search query text from other …

Sep 8, 2026
CVE-2026-86644
3.5 LOW

A vulnerability was determined in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web_src/public/editor.md/editormd.js of the component API Page Save …

Sep 8, 2026
CVE-2026-73318
3.8 LOW

XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any ACP administrator to access and submit force-agreement forms regardless of …

Sep 8, 2026
CVE-2026-73317
2.7 LOW

XenForo before 2.3.13 contains a missing authorization vulnerability in the ACP cache-rebuild dispatcher that allows limited administrators with only the rebuildCache permission to perform unauthorized …

Sep 8, 2026
CVE-2026-33920
3.5 LOW

A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token. An attacker …

Sep 8, 2026
CVE-2026-76961
3.5 LOW

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges …

Sep 8, 2026
CVE-2026-76960
3.5 LOW

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges …

Sep 8, 2026
CVE-2026-58234
2.2 LOW

SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily …

Sep 8, 2026
CVE-2026-86505
3.3 LOW

In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace

Sep 7, 2026
CVE-2026-86503
3.3 LOW

In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching

Sep 7, 2026
CVE-2026-86501
2.8 LOW

In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log

Sep 7, 2026
CVE-2026-86491
3.5 LOW

In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads

Sep 7, 2026
CVE-2026-86487
3.1 LOW

In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content

Sep 7, 2026
CVE-2026-86486
3.7 LOW

In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank

Sep 7, 2026
CVE-2026-86485
3.3 LOW

In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks

Sep 7, 2026
CVE-2026-86425
3.3 LOW

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted list of …

Sep 7, 2026
CVE-2026-86424
2.5 LOW

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink …

Sep 7, 2026
CVE-2026-86423
3.3 LOW

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList method of PerlMagick. A crafted call to the GetList method can …

Sep 7, 2026
CVE-2026-86422
3.3 LOW

ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink …

Sep 7, 2026
CVE-2026-86421
3.7 LOW

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing …

Sep 7, 2026
CVE-2026-86420
3.7 LOW

ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust …

Sep 7, 2026
CVE-2026-86301
3.5 LOW

A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. …

Sep 7, 2026
CVE-2025-52657
3.5 LOW

HCL MyXalytics was affected by Potential DOS Vulnerability. It allows users to input data without any restriction on the number of characters which can impact …

Sep 7, 2026
CVE-2025-52652
3.5 LOW

HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content, making it appear as though it originates from …

Sep 7, 2026
CVE-2025-52651
3.5 LOW

HCL MyXalytics was affected by Improper Input validation Vulnerability. It allow malicious or unexpected data to cause unintended system behaviour or security issues.

Sep 7, 2026
CVE-2026-86231
3.7 LOW

A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manipulation of …

Sep 6, 2026
CVE-2026-86227
3.1 LOW

A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the file src/kvstore.c. This manipulation of the argument …

Sep 6, 2026
CVE-2026-86226
3.5 LOW

A security flaw has been discovered in Projectwolds Online Attendance System 1.0. Affected by this issue is some unknown functionality of the file profile.php. The …

Sep 6, 2026
CVE-2021-48006
3.3 LOW

PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but only removes an …

Sep 6, 2026
CVE-2026-86181
3.5 LOW

A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the component …

Sep 6, 2026
CVE-2025-15614
3.3 LOW

ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files …

Sep 5, 2026
CVE-2026-84927
2.7 LOW

The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with …

Sep 5, 2026
CVE-2026-84926
2.7 LOW

The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user …

Sep 5, 2026
CVE-2026-84745
2.7 LOW

The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing …

Sep 5, 2026
CVE-2026-84225
2.2 LOW

The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing …

Sep 5, 2026
CVE-2026-81348
3.7 LOW

The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to …

Sep 5, 2026
CVE-2026-78150
2.7 LOW

The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users …

Sep 5, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.