CVE Database

116755+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-35342
3.3 LOW

The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR …

Apr 22, 2026
CVE-2026-35341
7.1 HIGH

A vulnerability in uutils coreutils mkfifo allows for the unauthorized modification of permissions on existing files. When mkfifo fails to create a FIFO because a …

Apr 22, 2026
CVE-2026-35340
5.5 MEDIUM

A flaw in the ChownExecutor used by uutils coreutils chown and chgrp causes the utilities to return an incorrect exit code during recursive operations. The …

Apr 22, 2026
CVE-2026-35339
5.5 MEDIUM

The recursive mode (-R) of the chmod utility in uutils coreutils incorrectly handles exit codes when processing multiple files. The final return value is determined …

Apr 22, 2026
CVE-2026-35338
7.3 HIGH

A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. The implementation only validates if the target path …

Apr 22, 2026
CVE-2026-32885
6.5 MEDIUM

DDEV is an open-source tool for running local web development environments for PHP and Node.js. Versions prior to 1.25.2 have unsanitized extraction in both `Untar()` …

Apr 22, 2026
CVE-2026-1660
6.5 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain …

Apr 22, 2026
CVE-2025-9957
2.7 LOW

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain …

Apr 22, 2026
CVE-2025-6016
6.5 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have …

Apr 22, 2026
CVE-2025-3922
6.5 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have …

Apr 22, 2026
CVE-2025-0186
6.5 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have …

Apr 22, 2026
CVE-2026-30139
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the AdvancedSearch functionality of Silverpeas Core before version 6.4.6 allows attackers to execute arbitrary JavaScript in the context …

Apr 22, 2026
CVE-2025-58922
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada allows Cross Site Request Forgery.This issue affects Avada: from n/a before 7.13.2.

Apr 22, 2026
CVE-2024-58344
6.4 MEDIUM

Carbon Forum 5.9.0 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript code through the Forum Name field in dashboard …

Apr 22, 2026
CVE-2018-25272
9.8 CRITICAL

ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with SYSTEM level permissions. Attackers can …

Apr 22, 2026
CVE-2018-25271
6.2 MEDIUM

Textpad 8.1.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long buffer string through the …

Apr 22, 2026
CVE-2018-25270
9.8 CRITICAL

ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functions through the routing parameter. Attackers …

Apr 22, 2026
CVE-2018-25269
6.1 MEDIUM

ICEWARP 11.0.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML elements into emails by embedding base64-encoded payloads in object and embed …

Apr 22, 2026
CVE-2018-25268
8.4 HIGH

LanSpy 2.0.1.159 contains a local buffer overflow vulnerability that allows attackers to overwrite the instruction pointer by supplying oversized input to the scan field. Attackers …

Apr 22, 2026
CVE-2018-25267
6.2 MEDIUM

UltraISO 9.7.1.3519 contains a local buffer overflow vulnerability in the Output FileName field of the Make CD/DVD Image dialog that allows attackers to overwrite SEH …

Apr 22, 2026
CVE-2018-25266
6.2 MEDIUM

Angry IP Scanner 3.5.3 contains a buffer overflow vulnerability in the preferences dialog that allows local attackers to crash the application by supplying an excessively …

Apr 22, 2026
CVE-2018-25265
8.4 HIGH

LanSpy 2.0.1.159 contains a local buffer overflow vulnerability in the scan section that allows local attackers to execute arbitrary code by exploiting structured exception handling …

Apr 22, 2026
CVE-2018-25262
6.2 MEDIUM

Angry IP Scanner for Linux 3.5.3 contains a denial of service vulnerability that allows local attackers to crash the application by supplying malformed input to …

Apr 22, 2026
CVE-2018-25261
8.4 HIGH

Iperius Backup 5.8.1 contains a local buffer overflow vulnerability in the structured exception handling (SEH) mechanism that allows local attackers to execute arbitrary code by …

Apr 22, 2026
CVE-2018-25260
8.4 HIGH

MAGIX Music Editor 3.1 contains a buffer overflow vulnerability in the FreeDB Proxy Options dialog that allows local attackers to execute arbitrary code by exploiting …

Apr 22, 2026
CVE-2018-25259
8.4 HIGH

Terminal Services Manager 3.1 contains a stack-based buffer overflow vulnerability in the computer names field that allows local attackers to execute arbitrary code by triggering …

Apr 22, 2026
CVE-2026-35548
8.5 HIGH

An issue was discovered in guardsix (formerly Logpoint) ODBC Enrichment Plugins before 5.2.1 (5.2.1 is used in guardsix 7.9.0.0). A logic flaw allowed stored database …

Apr 22, 2026
CVE-2026-6862
5.5 MEDIUM

A flaw was found in libefiboot, a component of efivar. The device path node parser in libefiboot fails to validate that each node's Length field …

Apr 22, 2026
CVE-2026-6861
6.1 MEDIUM

A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading …

Apr 22, 2026
CVE-2026-6859
8.8 HIGH

A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from HuggingFace. This allows a remote attacker to achieve arbitrary Python …

Apr 22, 2026
CVE-2026-6356
9.6 CRITICAL

A vulnerability in the web application allows standard users to escalate their privileges to those of a super administrator through parameter manipulation, enabling them to …

Apr 22, 2026
CVE-2026-6355
6.5 MEDIUM

A vulnerability in the web application allows unauthorized users to access and manipulate sensitive data across different tenants by exploiting insecure direct object references. This …

Apr 22, 2026
CVE-2026-5750

An insecure direct object reference (IDOR) vulnerability in the Fullstep V5 registration process allows authenticated users to access data belonging to other registered users through …

Apr 22, 2026
CVE-2026-5749

Inadequate access control in the registration process in Fullstep V5, which could allow unauthenticated users to obtain a valid JWT token with which to interact …

Apr 22, 2026
CVE-2026-41651
8.8 HIGH

PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between …

Apr 22, 2026
CVE-2026-33611
6.5 MEDIUM

An operator allowed to use the REST API can cause the Authoritative server to produce invalid HTTPS or SVCB record data, which can in turn …

Apr 22, 2026
CVE-2026-33610
5.9 MEDIUM

A rogue primary server may cause file descriptor exhaustion and eventually a denial of service, when a PowerDNS secondary server forwards a DNS update request …

Apr 22, 2026
CVE-2026-33609
5.3 MEDIUM

Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform queries of internal domain subtrees.

Apr 22, 2026
CVE-2026-33608
7.4 HIGH

An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to …

Apr 22, 2026
CVE-2026-33602
6.5 MEDIUM

A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds …

Apr 22, 2026
CVE-2026-33599
3.1 LOW

A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) option to …

Apr 22, 2026
CVE-2026-33598
4.8 MEDIUM

A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet cache.

Apr 22, 2026
CVE-2026-33597
3.7 LOW

PRSD detection denial of service

Apr 22, 2026
CVE-2026-33596
3.1 LOW

A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of …

Apr 22, 2026
CVE-2026-33595
5.3 MEDIUM

A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 connection, as some resources were …

Apr 22, 2026
CVE-2026-33594
5.3 MEDIUM

A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accumulate …

Apr 22, 2026
CVE-2026-33593
7.5 HIGH

A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query.

Apr 22, 2026
CVE-2026-33254
5.3 MEDIUM

An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial of …

Apr 22, 2026
CVE-2026-31530
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: cxl/port: Fix use after free of parent_port in cxl_detach_ep() cxl_detach_ep() is called during bottom-up removal …

Apr 22, 2026
CVE-2026-31529
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fix leakage in __construct_region() Failing the first sysfs_update_group() needs to explicitly kfree the resource …

Apr 22, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.