CVE Database

135211+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-59711
6.1 MEDIUM

showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitrary HTML and JavaScript. When completeHTMLDocument option is enabled, unescaped …

Jul 6, 2026
CVE-2026-57573
8.6 HIGH

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl …

Jul 6, 2026
CVE-2026-57572
10.0 CRITICAL

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromium's launch arguments. …

Jul 6, 2026
CVE-2026-57571
9.6 CRITICAL

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from …

Jul 6, 2026
CVE-2026-55727
7.5 HIGH

A flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14.178.18 may allow an unauthenticated attacker to …

Jul 6, 2026
CVE-2026-55574
7.5 HIGH

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_outputs.regex API parameter passes a user-supplied regular expression string …

Jul 6, 2026
CVE-2026-55514
6.5 MEDIUM

vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a /v1/completions request with …

Jul 6, 2026
CVE-2026-54765
8.5 HIGH

Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted …

Jul 6, 2026
CVE-2026-54764
5.8 MEDIUM

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middleware, even when configured with trustForwardHeader: false, derives …

Jul 6, 2026
CVE-2026-54763
10.0 CRITICAL

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity …

Jul 6, 2026
CVE-2026-54234
7.5 HIGH

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal multi-request speculative decoding workload can cause the rejection …

Jul 6, 2026
CVE-2026-50135
5.5 MEDIUM

Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made RootMappingFs.statRoot use Stat (follows symlinks) instead of Lstat , so a direct …

Jul 6, 2026
CVE-2026-48267
5.5 MEDIUM

DNG SDK versions 1.7.1 2536 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Jul 6, 2026
CVE-2026-42341

FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. …

Jul 6, 2026
CVE-2026-42331

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/update endpoint is missing an authorization check present …

Jul 6, 2026
CVE-2026-34038
9.9 CRITICAL

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application deployment …

Jul 6, 2026
CVE-2026-33734

FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a SQL injection vulnerability in the `Massmailer` module filter functionality. …

Jul 6, 2026
CVE-2026-25271
7.8 HIGH

Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.

Jul 6, 2026
CVE-2026-25268
8.8 HIGH

Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.

Jul 6, 2026
CVE-2026-21384
5.3 MEDIUM

Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.

Jul 6, 2026
CVE-2026-21383
7.1 HIGH

Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security.

Jul 6, 2026
CVE-2026-21379
7.8 HIGH

Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.

Jul 6, 2026
CVE-2026-21370
5.3 MEDIUM

Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.

Jul 6, 2026
CVE-2026-21369
5.3 MEDIUM

Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.

Jul 6, 2026
CVE-2026-21368
5.3 MEDIUM

Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.

Jul 6, 2026
CVE-2026-14471
8.1 HIGH

Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-gateway-registry before 1.0.13 might allow an authenticated remote user to execute …

Jul 6, 2026
CVE-2026-14468
7.7 HIGH

HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that did not correctly enforce the intended boundary on …

Jul 6, 2026
CVE-2025-59617
6.6 MEDIUM

Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.

Jul 6, 2026
CVE-2025-59616
6.6 MEDIUM

Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory.

Jul 6, 2026
CVE-2025-59615
6.6 MEDIUM

Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper synchronization.

Jul 6, 2026
CVE-2026-59089
5.5 MEDIUM

A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calculates the size of the Color Look-Up Table …

Jul 6, 2026
CVE-2026-58404
6.8 MEDIUM

Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests to loopback, internal, and cloud-metadata IPv4 literals, but the …

Jul 6, 2026
CVE-2026-58403
6.5 MEDIUM

Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's virtual filesystem is designed so that files under a mount cannot reach outside the …

Jul 6, 2026
CVE-2026-58402
5.4 MEDIUM

Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-fence language or info-string into the code class="language-…" …

Jul 6, 2026
CVE-2026-55646
6.5 MEDIUM

vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions and /v1/audio/translations routes call request.file.read() to fully materialize …

Jul 6, 2026
CVE-2026-53763
3.8 LOW

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting …

Jul 6, 2026
CVE-2026-50134
5.8 MEDIUM

Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.http.urls on the URL it is called with, but it did not re-validate …

Jul 6, 2026
CVE-2026-50133
6.1 MEDIUM

Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to the text/html media type (typically …

Jul 6, 2026
CVE-2026-44362
5.5 MEDIUM

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting …

Jul 6, 2026
CVE-2026-42546
3.8 LOW

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting …

Jul 6, 2026
CVE-2026-41516
2.5 LOW

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting …

Jul 6, 2026
CVE-2026-41515
2.5 LOW

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting …

Jul 6, 2026
CVE-2026-41514
2.5 LOW

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting …

Jul 6, 2026
CVE-2026-14898
6.5 MEDIUM

The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could place an indirect prompt injection in …

Jul 6, 2026
CVE-2026-14536
8.8 HIGH

Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypass the MFA Required policy …

Jul 6, 2026
CVE-2026-11405
9.8 CRITICAL

The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains a normal authentication path …

Jul 6, 2026
CVE-2026-9182
9.8 CRITICAL

Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. …

Jul 6, 2026
CVE-2026-9181
9.8 CRITICAL

Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending crafted …

Jul 6, 2026
CVE-2026-55798
4.5 MEDIUM

Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without …

Jul 6, 2026
CVE-2026-55380
7.5 HIGH

Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without …

Jul 6, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.