CVE Database

135211+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-55633

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and file dropper fix allows …

Jul 7, 2026
CVE-2026-55631

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the font management module allows authenticated users to submit an arbitrary fileTransName …

Jul 7, 2026
CVE-2026-55592
3.9 LOW

Dashy is a self-hostable personal dashboard. Prior to 4.3.7, Dashy's workspace view trusts the url query parameter and assigns it directly to an iframe source …

Jul 7, 2026
CVE-2026-55434
6.5 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.33.0 and prior to versions 2.33.8 and 2.34.2, AI Bridge provider handlers …

Jul 7, 2026
CVE-2026-55417

Chevereto is a self-hosted media-sharing platform. Starting in version 3.7.5 and prior to version 4.5.4, when a user enables the private profile option, visiting their …

Jul 7, 2026
CVE-2026-53935
6.9 MEDIUM

Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to …

Jul 7, 2026
CVE-2026-53751

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the H2 database JDBC URL validation logic can be bypassed with special …

Jul 7, 2026
CVE-2026-53730

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql endpoint lacks the mandatory @DePermit permission validation annotation, allowing any …

Jul 7, 2026
CVE-2026-53729

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, any authenticated user can download (/exportCenter/download/{id}), delete (/exportCenter/delete), retry (/exportCenter/retry/{id}), or generate …

Jul 7, 2026
CVE-2026-53511

calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when its metadata is read …

Jul 7, 2026
CVE-2026-50530

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface only validates that sceneId matches the …

Jul 7, 2026
CVE-2026-50529

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/share/proxyInfo share interface generates and returns X-DE-LINK-TOKEN before validating the share …

Jul 7, 2026
CVE-2026-50007

Actual is an open-source personal finance application. Prior to 26.7.0, a missing authorization issue allows a shared user with user_access on a budget file to …

Jul 7, 2026
CVE-2026-49471
8.3 HIGH

Serena is a powerful MCP toolkit for coding that provides semantic retrieval and editing capabilities. Prior to v1.5.2, Serena's built-in web dashboard exposes an unauthenticated …

Jul 7, 2026
CVE-2026-46700
4.3 MEDIUM

Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-server checks only that the caller has a valid session …

Jul 7, 2026
CVE-2026-46672
4.6 MEDIUM

Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in packages/cli/src/output.ts used whenever the global --format csv option …

Jul 7, 2026
CVE-2026-44454
8.1 HIGH

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30.2, the `dotfiles` registry module passed unsanitized user input to …

Jul 7, 2026
CVE-2026-58468
5.5 MEDIUM

NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows authenticated administrators to issue arbitrary outbound HTTP requests by supplying …

Jul 7, 2026
CVE-2026-44877
6.5 MEDIUM

An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful exploitation of this vulnerability could allow …

Jul 7, 2026
CVE-2026-7017
7.1 HIGH

HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header …

Jul 7, 2026
CVE-2026-59800
9.8 CRITICAL

9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-install endpoint (this route is not covered by the dashboard middleware matcher, …

Jul 7, 2026
CVE-2026-59708
7.5 HIGH

The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing unauthenticated access to full portfolio data. Attackers with a private …

Jul 7, 2026
CVE-2026-55435
5.4 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy …

Jul 7, 2026
CVE-2026-48958
8.8 HIGH

An improper access check allows unauthorized users to create custom fields via webservices endpoints.

Jul 7, 2026
CVE-2026-48957
8.8 HIGH

An improper access check allows unauthorized users to access com_privacy datasets.

Jul 7, 2026
CVE-2026-48956
5.0 MEDIUM

An improper access check allows users to display a list of modules in the frontend.

Jul 7, 2026
CVE-2026-48955
6.5 MEDIUM

An improper access check allows unauthorized users to access workflow stage and transition information.

Jul 7, 2026
CVE-2026-48954
6.1 MEDIUM

Improper validation leads to a generic XSS vector in the language override feature.

Jul 7, 2026
CVE-2026-48953
6.1 MEDIUM

Lack of escaping leads to an XSS vulnerability in the generic image output layout.

Jul 7, 2026
CVE-2026-48952
6.1 MEDIUM

Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.

Jul 7, 2026
CVE-2026-48951
6.1 MEDIUM

Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.

Jul 7, 2026
CVE-2026-48950
6.1 MEDIUM

Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.

Jul 7, 2026
CVE-2026-48949
6.1 MEDIUM

Lack of validation leads to an XSS vulnerability in the MFA management views.

Jul 7, 2026
CVE-2026-48948
8.8 HIGH

An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.

Jul 7, 2026
CVE-2026-48947
4.9 MEDIUM

An improper access check allows privileged users to overwrite media files without editing permissions.

Jul 7, 2026
CVE-2026-57851
7.8 HIGH

MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory …

Jul 7, 2026
CVE-2026-23698
7.2 HIGH

Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP …

Jul 7, 2026
CVE-2026-23697
8.8 HIGH

Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing …

Jul 7, 2026
CVE-2026-14904
6.5 MEDIUM

AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources …

Jul 7, 2026
CVE-2026-13020
8.1 HIGH

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, …

Jul 7, 2026
CVE-2026-13019
9.8 CRITICAL

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated …

Jul 7, 2026
CVE-2025-12799
6.5 MEDIUM

A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped characters …

Jul 7, 2026
CVE-2026-56812
7.5 HIGH

Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent …

Jul 7, 2026
CVE-2026-56811
7.5 HIGH

Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated attacker to cause a denial of service against any …

Jul 7, 2026
CVE-2026-14969
4.4 MEDIUM

A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an …

Jul 7, 2026
CVE-2026-14935
3.7 LOW

A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers …

Jul 7, 2026
CVE-2026-59709
4.3 MEDIUM

Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. Attackers with …

Jul 7, 2026
CVE-2026-53878
6.1 MEDIUM

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a …

Jul 7, 2026
CVE-2026-53877
4.8 MEDIUM

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which …

Jul 7, 2026
CVE-2026-48588
3.1 LOW

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when …

Jul 7, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.