CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-9537
5.3 MEDIUM

Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied signature to the recomputed HMAC …

Jul 17, 2026
CVE-2026-63100
6.5 MEDIUM

Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role users to access and modify global hosting settings by exploiting unprotected show …

Jul 17, 2026
CVE-2026-63099
6.5 MEDIUM

TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated user to access attachments belonging to other …

Jul 17, 2026
CVE-2026-63098
5.3 MEDIUM

TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a GET request to the …

Jul 17, 2026
CVE-2026-63097
4.3 MEDIUM

Dendrite through 0.13.8 contains an improper access control vulnerability in the syncapi /context endpoint (syncapi/routing/context.go) that allows authenticated local users to access post-leave room state …

Jul 17, 2026
CVE-2026-63096
5.8 MEDIUM

Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbound TLS connections to arbitrary hosts …

Jul 17, 2026
CVE-2026-63095
6.5 MEDIUM

Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party identifier bindings belonging …

Jul 17, 2026
CVE-2026-60025
8.8 HIGH

The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.

Jul 17, 2026
CVE-2026-60024
9.8 CRITICAL

The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.

Jul 17, 2026
CVE-2026-58149
5.3 MEDIUM

The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses.

Jul 17, 2026
CVE-2026-58148

The Joomla extension ChronoForms is vulnerable to an unauthenticated stored XSS vulnerability.

Jul 17, 2026
CVE-2026-15783

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata from …

Jul 17, 2026
CVE-2026-15343

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write …

Jul 17, 2026
CVE-2026-15007

A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release …

Jul 17, 2026
CVE-2026-14871

osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem.

Jul 17, 2026
CVE-2026-14741
7.5 HIGH

HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date. parse_date() matches the date string against a chain of alternative …

Jul 17, 2026
CVE-2026-12715

Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code …

Jul 17, 2026
CVE-2026-63094
8.1 HIGH

SigNoz through 0.133.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on …

Jul 17, 2026
CVE-2026-63093
8.8 HIGH

Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file …

Jul 17, 2026
CVE-2026-51083
6.5 MEDIUM

Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privileges to obtain hashed passwords …

Jul 17, 2026
CVE-2026-51082
7.2 HIGH

A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4.19; qemu-server 9.x …

Jul 17, 2026
CVE-2026-51081
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows attackers to execute arbitrary web …

Jul 17, 2026
CVE-2026-16089
5.4 MEDIUM

A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly …

Jul 17, 2026
CVE-2026-16017
6.3 MEDIUM

A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. Impacted is the function list/remove of the file tools/tool_cron.go of the component cron …

Jul 17, 2026
CVE-2026-12705
6.4 MEDIUM

Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE). This issue affects KNX Update Tool (ABB): through …

Jul 17, 2026
CVE-2026-9592

SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, …

Jul 17, 2026
CVE-2026-7488
7.5 HIGH

Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data. This issue affects E-Commerce: through 03062026.

Jul 17, 2026
CVE-2026-51080
9.8 CRITICAL

libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.

Jul 17, 2026
CVE-2026-16072
4.9 MEDIUM

A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a …

Jul 17, 2026
CVE-2026-16016
7.3 HIGH

A vulnerability was identified in poco-ai poco-claw up to 0.5.4. This issue affects the function run_task of the file executor/app/api/v1/task.py. The manipulation of the argument …

Jul 17, 2026
CVE-2026-16015
6.3 MEDIUM

A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of the file executor_manager/app/api/v1/tasks.py of the component executor_manager API. …

Jul 17, 2026
CVE-2025-60357
8.1 HIGH

AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEvent/list endpoint.

Jul 17, 2026
CVE-2024-42214
5.3 MEDIUM

HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the …

Jul 17, 2026
CVE-2024-23578
4.2 MEDIUM

HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from …

Jul 17, 2026
CVE-2024-23577
4.3 MEDIUM

HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requested in http protocol. …

Jul 17, 2026
CVE-2024-23575
5.3 MEDIUM

HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker …

Jul 17, 2026
CVE-2024-23574
5.3 MEDIUM

HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid …

Jul 17, 2026
CVE-2024-23573
3.7 LOW

HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 …

Jul 17, 2026
CVE-2024-23572
4.2 MEDIUM

HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You …

Jul 17, 2026
CVE-2024-23571
4.3 MEDIUM

HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and …

Jul 17, 2026
CVE-2024-23570
4.3 MEDIUM

HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on …

Jul 17, 2026
CVE-2024-23569
4.3 MEDIUM

HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header

Jul 17, 2026
CVE-2024-23568
5.3 MEDIUM

HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information …

Jul 17, 2026
CVE-2024-23567
4.3 MEDIUM

HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during …

Jul 17, 2026
CVE-2024-23566
6.5 MEDIUM

HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force …

Jul 17, 2026
CVE-2024-23565
5.3 MEDIUM

HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor …

Jul 17, 2026
CVE-2024-23564
9.1 CRITICAL

HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and …

Jul 17, 2026
CVE-2026-8396
7.5 HIGH

Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Data External Linking. This issue affects NetGIS: from 5.0.66 before …

Jul 17, 2026
CVE-2026-7189
7.5 HIGH

Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue …

Jul 17, 2026
CVE-2026-16014
7.3 HIGH

A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the component Login Form. Performing a manipulation of …

Jul 17, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.