CVE Database

134505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-44383
7.5 HIGH

Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to deploy multiple instances of malicious OCPP …

Jul 10, 2026
CVE-2026-42952
7.5 HIGH

Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could allow an attacker to execute a denial-of-service attack.

Jul 10, 2026
CVE-2026-20744
9.8 CRITICAL

The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation.

Jul 10, 2026
CVE-2026-15089
9.1 CRITICAL

vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*.

Jul 10, 2026
CVE-2026-15087
5.9 MEDIUM

vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.

Jul 10, 2026
CVE-2026-15086
5.9 MEDIUM

vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*.

Jul 10, 2026
CVE-2026-14480
9.9 CRITICAL

OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application stores an attacker‑supplied filename (prog_file) directly …

Jul 10, 2026
CVE-2026-14286

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 10, 2026
CVE-2026-11915
5.9 MEDIUM

vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*.

Jul 10, 2026
CVE-2026-11914
5.9 MEDIUM

vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*.

Jul 10, 2026
CVE-2026-11913
9.8 CRITICAL

vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.

Jul 10, 2026
CVE-2026-59155

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to 2.2.5, the GET /api/v1/ddns and GET /api/v1/notification endpoints return full …

Jul 10, 2026
CVE-2026-58591
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS). This issue affects Colorbox versions: from 0.0.0 …

Jul 10, 2026
CVE-2026-58590
5.4 MEDIUM

Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.

Jul 10, 2026
CVE-2026-58589
5.4 MEDIUM

Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.

Jul 10, 2026
CVE-2026-58588
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: …

Jul 10, 2026
CVE-2026-58587
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: …

Jul 10, 2026
CVE-2026-58503

Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed …

Jul 10, 2026
CVE-2026-57584

Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.0, every Phalcon MVC application built with a default router registers a built-in route whose compiled …

Jul 10, 2026
CVE-2026-55884

Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP server registers handlers on a gorilla/mux …

Jul 10, 2026
CVE-2026-55883

Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.24.0 through 0.37.3, the Tilt HUD WebSocket at /ws/view is gated by a …

Jul 10, 2026
CVE-2026-55882

Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.19.5 through 0.37.3, the Tilt HUD server mounts Go net/http/pprof handlers under /debug …

Jul 10, 2026
CVE-2026-55852

Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, TarSlip RCE was possible in Package Import because tarfile members were not sufficiently …

Jul 10, 2026
CVE-2026-55810
8.1 HIGH

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2.

Jul 10, 2026
CVE-2026-55809
8.1 HIGH

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance field allows Object Injection. This issue affects Flag attendance field versions: from 0.0.0 …

Jul 10, 2026
CVE-2026-55808
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: …

Jul 10, 2026
CVE-2026-55807
3.1 LOW

Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from …

Jul 10, 2026
CVE-2026-55806
5.9 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, …

Jul 10, 2026
CVE-2026-55804
5.9 MEDIUM

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, …

Jul 10, 2026
CVE-2026-55803
5.9 MEDIUM

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, …

Jul 10, 2026
CVE-2026-55187
5.8 MEDIUM

Mailpit is an email testing tool and API for developers. Prior to 1.30.2, the remediation shipped for CVE-2026-27808 is incomplete because the tools.IsInternalIP deny-list in …

Jul 10, 2026
CVE-2026-54736

Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the attacker-supplied HMAC tag against the freshly computed HMAC using PHP/Zephir identity comparison, …

Jul 10, 2026
CVE-2026-52761
5.8 MEDIUM

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 through 3.0.15, the t:utf8toUnicode transformation in …

Jul 10, 2026
CVE-2026-52747
8.6 HIGH

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser …

Jul 10, 2026
CVE-2026-49844
5.9 MEDIUM

Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache …

Jul 10, 2026
CVE-2026-49394

Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_page endpoint in Workspace because public workspaces did not …

Jul 10, 2026
CVE-2026-49213
8.1 HIGH

TypeBot is a chatbot builder tool. Prior to 3.17.2, Typebot's shared SSRF validator in packages/lib/src/ssrf/validateHttpReqUrl.ts can be bypassed with the IPv6 unspecified address :: because …

Jul 10, 2026
CVE-2026-48127

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach files to any doctype through file-handling API …

Jul 10, 2026
CVE-2026-47422

Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and that has since been …

Jul 10, 2026
CVE-2026-47199

Frappe is a full-stack web application framework. Prior to 16.18.3 and 15.108.0, check_safe_sql_query permitted SELECT INTO OUTFILE queries, which could potentially work on self-hosted sites …

Jul 10, 2026
CVE-2026-44795
8.8 HIGH

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation …

Jul 10, 2026
CVE-2026-42219

Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, path traversal via download_backups was possible due to lack of hardening. This issue …

Jul 10, 2026
CVE-2026-41482

Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion were possible through secure local resource access in …

Jul 10, 2026
CVE-2026-15085
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI SEO/GEO Analyzer allows Stored XSS. This issue affects AI SEO/GEO Analyzer …

Jul 10, 2026
CVE-2026-15084
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Patterns (SDC in Drupal UI) allows Stored XSS. This issue affects …

Jul 10, 2026
CVE-2026-15083
4.2 MEDIUM

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Condition - Action allows Object Injection. This issue affects ECA: Event - …

Jul 10, 2026
CVE-2026-15082
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Siteimprove Analytics allows Cross-Site Scripting (XSS). This issue affects Siteimprove Analytics versions: …

Jul 10, 2026
CVE-2026-15081
7.4 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection. This issue affects Location Selector …

Jul 10, 2026
CVE-2026-15080
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery. This issue affects Ray Enterprise Translation versions: from 0.0.0 to …

Jul 10, 2026
CVE-2026-15079
5.4 MEDIUM

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute Force. This issue affects Login Disable versions: from 0.0.0 to 2.1.4.

Jul 10, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.