CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-73737
4.8 MEDIUM

An unauthenticated path traversal vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to manipulate …

Sep 1, 2026
CVE-2026-73736
5.3 MEDIUM

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files. Successful exploitation …

Sep 1, 2026
CVE-2026-73735
5.4 MEDIUM

Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to access some information beyond their privilege level. …

Sep 1, 2026
CVE-2026-73734
5.4 MEDIUM

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to redirect users to an arbitrary URL.

Sep 1, 2026
CVE-2026-73733
5.4 MEDIUM

Authentication bypasses in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to circumvent existing authentication controls. Successful exploitation …

Sep 1, 2026
CVE-2026-73732
5.6 MEDIUM

A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to obtain …

Sep 1, 2026
CVE-2026-73731
6.1 MEDIUM

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a reflected cross-site scripting (XSS) …

Sep 1, 2026
CVE-2026-73730
6.5 MEDIUM

A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change …

Sep 1, 2026
CVE-2026-73729
6.5 MEDIUM

A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to upstream …

Sep 1, 2026
CVE-2026-73728
6.5 MEDIUM

Denial-of-service vulnerabilities exist in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of …

Sep 1, 2026
CVE-2026-73727
6.5 MEDIUM

Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to access sensitive information. A successful exploit allows …

Sep 1, 2026
CVE-2026-73726
6.8 MEDIUM

A vulnerability has been identified in the underlying operating system of HPE Networking Fabric Composer that could potentially allow an unauthenticated adjacent actor to circumvent …

Sep 1, 2026
CVE-2026-72682
6.5 MEDIUM

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding …

Sep 1, 2026
CVE-2026-72654
6.5 MEDIUM

Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users …

Sep 1, 2026
CVE-2026-72652
6.5 MEDIUM

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can …

Sep 1, 2026
CVE-2026-72644
6.5 MEDIUM

Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only the low-privileged feature …

Sep 1, 2026
CVE-2026-72641
5.4 MEDIUM

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding …

Sep 1, 2026
CVE-2026-72633
4.3 MEDIUM

Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An …

Sep 1, 2026
CVE-2026-72628
6.5 MEDIUM

Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding Streams …

Sep 1, 2026
CVE-2026-63138
6.5 MEDIUM

Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-676). An authenticated user with …

Sep 1, 2026
CVE-2026-56143
4.9 MEDIUM

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated …

Sep 1, 2026
CVE-2026-33465
6.5 MEDIUM

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with …

Sep 1, 2026
CVE-2026-84306
6.5 MEDIUM

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.6 and 5.7.6, packages/panels/src/Auth/MultiFactor/App/AppAuthentication.php uses AppAuthentication::verifyCode() with a used-code cache key …

Sep 1, 2026
CVE-2026-84270
4.3 MEDIUM

A flaw was found in the MTP backend in gvfs. When reading a file from a mounted MTP device, do_read() in gvfsbackendmtp.c trusts the data …

Sep 1, 2026
CVE-2026-84269
6.5 MEDIUM

A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to …

Sep 1, 2026
CVE-2026-84267
4.3 MEDIUM

A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer …

Sep 1, 2026
CVE-2026-84232
5.4 MEDIUM

A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for …

Sep 1, 2026
CVE-2026-84207
5.4 MEDIUM

Heym before 0.0.98 fails to apply SSRF egress guards to WebSocket Send and WebSocket Trigger nodes, allowing authenticated users to connect to internal services. Attackers …

Sep 1, 2026
CVE-2026-84206
4.3 MEDIUM

Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets. …

Sep 1, 2026
CVE-2026-84205
6.5 MEDIUM

GROWI contains an access control vulnerability in the GET /_api/v3/revisions/:id endpoint that validates access against a query parameter but returns the revision identified by the …

Sep 1, 2026
CVE-2026-84204
6.5 MEDIUM

GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fails to validate page access permissions. Authenticated attackers can retrieve attachment metadata from …

Sep 1, 2026
CVE-2026-84153
6.3 MEDIUM

A vulnerability was determined in Xinhu Rainrock RockOA up to 2.3.2. The impacted element is the function toaddval of the file /index.php?m=index&a=publicsavevalue&ajaxbool=true. Executing a manipulation …

Sep 1, 2026
CVE-2026-84114
6.3 MEDIUM

A vulnerability has been found in Cleo Harmony up to 5.8.1.10. Impacted is the function LocalUserUtil.getNativeUserByAssertions of the component SAML Authentication. Such manipulation of the …

Sep 1, 2026
CVE-2026-84110
5.3 MEDIUM

A vulnerability was detected in Releasit Releasit COD Form & Upsells v1. This vulnerability affects unknown code of the component OTP Validation. The manipulation results …

Sep 1, 2026
CVE-2026-83557
5.6 MEDIUM

DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set …

Sep 1, 2026
CVE-2026-79685
6.5 MEDIUM

Dell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to gain unauthorized access to sensitive sensitive …

Sep 1, 2026
CVE-2026-84109
6.3 MEDIUM

A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. Affected by this issue is the function getOrder of the file webmain/webmainAction.php. Executing …

Sep 1, 2026
CVE-2026-51761
5.3 MEDIUM

Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a crafted MQTT …

Sep 1, 2026
CVE-2026-51756
5.9 MEDIUM

Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a …

Sep 1, 2026
CVE-2026-51752
5.3 MEDIUM

Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the configured master via sending …

Sep 1, 2026
CVE-2026-51748
5.9 MEDIUM

Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory records via sending a crafted MQTT …

Sep 1, 2026
CVE-2026-84127
4.3 MEDIUM

Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 155.

Sep 1, 2026
CVE-2026-84126
4.3 MEDIUM

Incorrect boundary conditions in the Layout: Grid component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

Sep 1, 2026
CVE-2026-84125
5.4 MEDIUM

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Sep 1, 2026
CVE-2026-84124
5.4 MEDIUM

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, …

Sep 1, 2026
CVE-2026-84122
5.4 MEDIUM

Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Sep 1, 2026
CVE-2026-84120
5.4 MEDIUM

Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, …

Sep 1, 2026
CVE-2026-84118
5.4 MEDIUM

Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Sep 1, 2026
CVE-2026-84061
6.3 MEDIUM

A security flaw has been discovered in zhongyu09 OpenChatBI up to 0.3.0. Affected by this vulnerability is the function _validate_sql_safety of the file openchatbi/text2sql/generate_sql.py. Performing …

Sep 1, 2026
CVE-2026-7877
6.4 MEDIUM

The WP Recipe Maker Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-call-to-action' shortcode in all versions up to, and …

Sep 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.