CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-82797
5.5 MEDIUM

Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads. This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51.

Aug 31, 2026
CVE-2026-76984
5.4 MEDIUM

Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.head.MetaDataHeaderItem generates <meta> and <link> header tags. It escaped the attribute names it wrote, …

Aug 31, 2026
CVE-2026-76983
5.4 MEDIUM

Improper neutralization of input during web page generation in Apache Wicket. The <wicket:label> tag is provided by org.apache.wicket.markup.html.form.AutoLabelTextResolver, which is registered by default in every …

Aug 31, 2026
CVE-2026-76982
5.4 MEDIUM

Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.Button clears the escape-model-strings flag in its constructor, so that the value attribute it …

Aug 31, 2026
CVE-2026-75802
5.4 MEDIUM

AjaxEditableChoiceLabel in wicket-extensions, when constructed with a non-null IChoiceRenderer, writes the display value obtained from that renderer into the label's markup without applying the HTML …

Aug 31, 2026
CVE-2026-71378
4.6 MEDIUM

ResourceIsolationRequestCycleListener protects a Wicket application against cross-site request forgery by rejecting requests that a resource isolation policy judges to come from another origin. Its default …

Aug 31, 2026
CVE-2026-70449
5.3 MEDIUM

Improper validation of resource URL attributes in Apache Wicket allows an unauthenticated remote attacker to read files from the web application, including files under WEB-INF …

Aug 31, 2026
CVE-2026-82881
5.4 MEDIUM

Aix-DB through 1.2.4 renders markdown with raw HTML enabled into v-html bindings without sanitization, allowing stored cross-site scripting attacks. Attackers can inject malicious HTML and …

Aug 31, 2026
CVE-2026-82879
6.3 MEDIUM

DataEase before 2.10.26 contains multiple access control defects in the sharing link module. Tickets are not bound to the target share UUID, so a valid …

Aug 31, 2026
CVE-2026-82878
6.3 MEDIUM

DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard linkage, and chart detail REST endpoints, allowing authenticated users to access resources belonging …

Aug 31, 2026
CVE-2026-82877
6.5 MEDIUM

ILIAS versions before 9.22, 10.0 through 10.9, and 11.0 through 11.2 contain an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated …

Aug 31, 2026
CVE-2026-82679
6.3 MEDIUM

A security flaw has been discovered in diem-project diem up to 5.1.3. The impacted element is an unknown function of the file dmFrontPlugin/lib/dmWidget/media/dmWidgetContentBaseMediaForm.php of the …

Aug 31, 2026
CVE-2026-82678
4.7 MEDIUM

A vulnerability was identified in diem-project diem up to 5.1.3. The affected element is the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of the component Administrative …

Aug 31, 2026
CVE-2026-82670
4.4 MEDIUM

A flaw has been found in IObit Uninstaller 15.5.0.11. This affects the function IRP_MJ_DEVICE_CONTROL in the library IUForceDelete.sys of the component IOCTL Handler. Executing a …

Aug 31, 2026
CVE-2026-82669
5.3 MEDIUM

A vulnerability was detected in klaussilveira GitList 2.0.0. Affected by this issue is the function SimpleXMLElement of the file src/SCM/System/Git/CommandLine.php of the component XML Parsing. …

Aug 31, 2026
CVE-2026-82875
5.5 MEDIUM

ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user's …

Aug 31, 2026
CVE-2026-82873
5.0 MEDIUM

ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerabilities in the POST /api/v2/resources/export endpoint that allow authenticated users to disclose TooljetDB table schemas across workspace boundaries and …

Aug 31, 2026
CVE-2026-82868
6.1 MEDIUM

@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the SVG schema plugin that renders user-supplied SVG content directly to innerHTML without sanitization. Attackers can …

Aug 31, 2026
CVE-2026-82867
6.1 MEDIUM

@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the Select schema plugin that fails to sanitize option values before interpolating them into HTML via …

Aug 31, 2026
CVE-2026-82866
6.8 MEDIUM

@pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function that fetches arbitrary URLs without validation when basePdf is attacker-controlled. Attackers who …

Aug 31, 2026
CVE-2026-82865
4.4 MEDIUM

pdfme schemas before 5.5.10 contains a cross-site scripting vulnerability in the multiVariableText property panel that assigns unsanitized i18n label values to innerHTML. Attackers who control …

Aug 31, 2026
CVE-2026-82864
6.5 MEDIUM

pdfme pdf-lib versions before 5.5.10 contain an unbounded buffer growth vulnerability in the DecodeStream.ensureBuffer() method that allows attackers to cause denial of service by supplying …

Aug 31, 2026
CVE-2026-82853
4.9 MEDIUM

Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly …

Aug 31, 2026
CVE-2026-82667
4.7 MEDIUM

A vulnerability has been found in yaojingang GEOFlow up to 2.1.0. Impacted is the function DistributionController.isValidHttpEndpoint of the file app/Services/GeoFlow/GenericHttpEndpointResolver.php. Such manipulation of the argument …

Aug 31, 2026
CVE-2026-82666
4.7 MEDIUM

A flaw has been found in yaojingang GEOFlow up to 2.1.0. This issue affects the function preview of the file app/Http/Controllers/Admin/SiteThemeEditorController.php of the component Superadmin …

Aug 31, 2026
CVE-2026-82664
4.3 MEDIUM

A security vulnerability has been detected in yaojingang GEOFlow up to 2.1.0. This affects an unknown part of the file app/Http/Controllers/Site/HomeController.php of the component JSON-LD …

Aug 31, 2026
CVE-2026-82662
6.5 MEDIUM

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can …

Aug 31, 2026
CVE-2026-82661
5.4 MEDIUM

Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker …

Aug 31, 2026
CVE-2026-82660
5.4 MEDIUM

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying …

Aug 31, 2026
CVE-2024-58379
5.3 MEDIUM

nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers …

Aug 31, 2026
CVE-2026-82629
4.7 MEDIUM

A vulnerability was determined in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This issue affects the function MyJwWebJwid3Controller.doUpload of the file jeewx-boot-module-weixin/src/main/java/com/jeecg/p3/open/web/back/MyJwWebJwid3Controller.java of the component doUpload Endpoint. …

Aug 31, 2026
CVE-2026-58301
6.5 MEDIUM

When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that causes the server to initiate …

Aug 31, 2026
CVE-2026-82625
4.3 MEDIUM

A vulnerability has been found in code-projects Simple Inventory System 1.0. This affects an unknown part of the file /register.php of the component User Registration. …

Aug 31, 2026
CVE-2026-82624
5.3 MEDIUM

A flaw has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file inventorymanagement.sql of the …

Aug 31, 2026
CVE-2026-82623
5.3 MEDIUM

A vulnerability was detected in open62541 up to 1.5.5. Affected by this vulnerability is the function UA_DataValue_backend_copyRange of the file plugins/historydata/ua_history_data_backend_memory.c of the component History …

Aug 31, 2026
CVE-2026-77013
5.3 MEDIUM

The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not restrict which of its handler methods a request may invoke, and performs no capability or nonce check …

Aug 31, 2026
CVE-2026-68951
5.3 MEDIUM

GROWI contains an incorrect authorization vulnerability. If this vulnerability is exploited, an unauthenticated attacker could retrieve the other user's bookmark data.

Aug 31, 2026
CVE-2026-53620
6.3 MEDIUM

GROWI contains a vulnerability with an authorization bypass through user-controlled key in the bookmark folder APIs. If this vulnerability is exploited, an authenticated attacker could …

Aug 31, 2026
CVE-2026-40465
5.3 MEDIUM

NSP is vulnerable to an open redirect due to insufficient server-side validation of the URL (or redirect) parameter.

Aug 31, 2026
CVE-2026-40464
5.4 MEDIUM

NSP is vulnerable to a stored XSS due to insufficient validation or encoding of user-controlled input in a workflow application. An authenticated attacker with access …

Aug 31, 2026
CVE-2026-82620
6.3 MEDIUM

A security flaw has been discovered in Soarkey StudentManagement and 学生信息管理系统 up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. This affects the function CourseDao.course_ranking of the file code/src/dao/CourseDao.java. Performing a …

Aug 31, 2026
CVE-2026-82619
4.3 MEDIUM

A vulnerability was identified in Systerel S2OPC up to 1.7.3. The impacted element is the function monitored_item_event_filter_treatment_bs__init_event_filter_ctx_and_result of the file src/ClientServer/services/bgenc/subscription_mgr.c. Such manipulation of the …

Aug 31, 2026
CVE-2026-82618
4.3 MEDIUM

A vulnerability was determined in Systerel S2OPC up to 1.7.3. The affected element is the function set_range_matrix_on_string_array of the file src/Common/opcua_types/sopc_builtintypes.c of the component String …

Aug 31, 2026
CVE-2026-82609
6.3 MEDIUM

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit.php. The manipulation of the argument …

Aug 31, 2026
CVE-2026-82605
4.3 MEDIUM

A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such …

Aug 31, 2026
CVE-2026-82604
4.3 MEDIUM

A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes …

Aug 31, 2026
CVE-2026-82603
5.4 MEDIUM

A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The …

Aug 31, 2026
CVE-2026-82602
5.3 MEDIUM

A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization …

Aug 31, 2026
CVE-2026-82601
4.3 MEDIUM

A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument …

Aug 31, 2026
CVE-2026-82599
5.4 MEDIUM

A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar …

Aug 31, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.