CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-79630
5.3 MEDIUM

The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump is the product that bump's discount was …

Sep 4, 2026
CVE-2026-74853
6.8 MEDIUM

The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above …

Sep 4, 2026
CVE-2026-71216
5.3 MEDIUM

PagerDuty alarm hook transmits the integration routing key over cleartext HTTP. PagerDuty serves this endpoint over HTTPS and will normally answer plain HTTP with a …

Sep 4, 2026
CVE-2026-17517
5.3 MEDIUM

The Content Views WordPress plugin before 4.5.1.2 does not check whether the user requesting a view is allowed to read the posts it returns, allowing …

Sep 4, 2026
CVE-2025-15691
5.3 MEDIUM

The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying …

Sep 4, 2026
CVE-2026-84431
4.4 MEDIUM

A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component com.airasia.mobile. Performing a …

Sep 2, 2026
CVE-2026-82968
6.4 MEDIUM

A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their …

Sep 2, 2026
CVE-2026-84701
5.4 MEDIUM

NocoBase fails to sanitize rich text field values in the read renderer, allowing users with create permissions to store malicious HTML with event handlers. Attackers …

Sep 2, 2026
CVE-2026-84698
6.5 MEDIUM

PX4 Autopilot contains a heap buffer overflow vulnerability in the sd_bench command that writes a four-byte block number into a user-supplied sized allocation. Attackers can …

Sep 2, 2026
CVE-2026-84697
5.3 MEDIUM

Mailpit's IsInternalIP deny list function fails to block the Azure WireServer address 168.63.129.16 and the RFC 2765/6145 IPv4-translated IPv6 prefix, allowing server-side request forgery to …

Sep 2, 2026
CVE-2026-84430
6.3 MEDIUM

A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vulnerability affects the function update of the file app/home/controller/Index.php of the component edit_personal …

Sep 2, 2026
CVE-2026-84427
4.3 MEDIUM

A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affected is an unknown function of the file agent/tools/bash/bash.py of the component Bash Tool. Executing …

Sep 2, 2026
CVE-2026-84425
4.3 MEDIUM

A vulnerability was found in zhayujie CowAgent up to 2.1.3. This impacts the function BrowserTool of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing …

Sep 2, 2026
CVE-2026-84483
5.3 MEDIUM

WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthenticated attackers to compute valid HMAC tokens using the public site …

Sep 1, 2026
CVE-2026-84477
5.4 MEDIUM

AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts. Unauthenticated attackers can access remindMe.php to execute …

Sep 1, 2026
CVE-2026-84373
5.9 MEDIUM

Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 and 5.0.0-rc.2, the public mockerPlugin and standalone interceptorPlugin exports in packages/mocker/src/node/interceptorPlugin.ts register the …

Sep 1, 2026
CVE-2026-84289
4.3 MEDIUM

A vulnerability was found in NousResearch hermes-agent up to 0.18.2. This vulnerability affects the function list_tools of the file tools/mcp_tool.py of the component MCP Tool. …

Sep 1, 2026
CVE-2026-84288
4.3 MEDIUM

A vulnerability has been found in NousResearch hermes-agent up to 0.18.2. This affects the function HermesACPAgent.prompt of the file acp_adapter/session.py of the component ACP Prompt …

Sep 1, 2026
CVE-2026-84470
6.4 MEDIUM

A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level …

Sep 1, 2026
CVE-2026-84371
5.4 MEDIUM

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, …

Sep 1, 2026
CVE-2026-84369
6.1 MEDIUM

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, …

Sep 1, 2026
CVE-2026-84365
6.5 MEDIUM

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix released for CVE-2026-39408 does not cover …

Sep 1, 2026
CVE-2026-84364
5.3 MEDIUM

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, when parseBody() expands dot-separated form field names into nested …

Sep 1, 2026
CVE-2026-84363
5.9 MEDIUM

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, Hono's query helpers treat a question mark after a …

Sep 1, 2026
CVE-2026-84287
4.3 MEDIUM

A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is some unknown functionality of the file gateway/platforms/api_server.py of the component Session …

Sep 1, 2026
CVE-2026-73783
4.9 MEDIUM

Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service condition on the …

Sep 1, 2026
CVE-2026-73772
6.5 MEDIUM

Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted packets to the …

Sep 1, 2026
CVE-2026-73762
6.6 MEDIUM

A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases …

Sep 1, 2026
CVE-2026-73761
6.5 MEDIUM

An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially crafted packet. …

Sep 1, 2026
CVE-2026-73760
6.5 MEDIUM

An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to read arbitrary files from the web-based management interface …

Sep 1, 2026
CVE-2026-73759
6.5 MEDIUM

Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities …

Sep 1, 2026
CVE-2026-73758
6.5 MEDIUM

A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the state …

Sep 1, 2026
CVE-2026-73757
6.4 MEDIUM

A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful …

Sep 1, 2026
CVE-2026-73756
5.9 MEDIUM

A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows …

Sep 1, 2026
CVE-2026-73755
5.7 MEDIUM

A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, …

Sep 1, 2026
CVE-2026-73754
5.3 MEDIUM

Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation could allow an authenticated user to disrupt the normal operation of a vulnerable …

Sep 1, 2026
CVE-2026-73524
6.1 MEDIUM

Cypht before 2.12.2 contains a cross-site scripting vulnerability in the contacts module that allows remote attackers to execute arbitrary script content by embedding malicious payloads …

Sep 1, 2026
CVE-2026-63435
5.3 MEDIUM

Mail is an internet library for Ruby designed to handle email generation, parsing, and sending. Prior to 2.9.1, Mail::Utilities.q_value_decode and Mail::Utilities.b_value_decode used a single String#match …

Sep 1, 2026
CVE-2026-84308
6.3 MEDIUM

phpseclib is a PHP secure communications library. Prior to 3.0.57 and 4.0.1, pure-PHP X25519 scalar multiplication in phpseclib/Math/PrimeField/Integer.php performs data-dependent conditional modular reductions in add() …

Sep 1, 2026
CVE-2026-78608
6.5 MEDIUM

Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to an internal Kibana APM …

Sep 1, 2026
CVE-2026-78607
5.4 MEDIUM

Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges …

Sep 1, 2026
CVE-2026-78606
4.2 MEDIUM

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Where …

Sep 1, 2026
CVE-2026-78605
5.9 MEDIUM

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to information disclosure via HTTP Request Smuggling (CAPEC-33). Under specific proxy deployment …

Sep 1, 2026
CVE-2026-78603
4.3 MEDIUM

Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch …

Sep 1, 2026
CVE-2026-78597
4.3 MEDIUM

Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creation via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An …

Sep 1, 2026
CVE-2026-73742
4.3 MEDIUM

A vulnerability in an API endpoint of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to spoof the source address attributed …

Sep 1, 2026
CVE-2026-73741
4.3 MEDIUM

A vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to view some system files. Successful exploitation …

Sep 1, 2026
CVE-2026-73740
4.4 MEDIUM

A local privilege escalation vulnerability in HPE Networking Fabric Composer could allow an authenticated privileged user on the underlying host to elevate their user privileges …

Sep 1, 2026
CVE-2026-73739
4.4 MEDIUM

A vulnerability exists in the API of HPE Networking Fabric Composer that allows for an attacker with administrative privileges to access sensitive information in a …

Sep 1, 2026
CVE-2026-73738
4.7 MEDIUM

A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to view …

Sep 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.