CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-43977
7.5 HIGH

wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read another user's private workout session notes, …

Jul 16, 2026
CVE-2026-15997

Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffers. This vulnerability is associated with program files https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/shake.C, …

Jul 16, 2026
CVE-2026-14253

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 16, 2026
CVE-2026-11740

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 16, 2026
CVE-2026-62826
4.6 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jul 16, 2026
CVE-2026-59117
7.5 HIGH

Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.

Jul 16, 2026
CVE-2026-58643
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.

Jul 16, 2026
CVE-2026-58598
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.

Jul 16, 2026
CVE-2026-57077
7.7 HIGH

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In the bundled libsyck newline_len and is_newline dereference …

Jul 16, 2026
CVE-2026-57076
7.8 HIGH

YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor. In the bundled libsyck …

Jul 16, 2026
CVE-2026-57075
9.1 CRITICAL

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec. The base64 decoder in the bundled libsyck indexes …

Jul 16, 2026
CVE-2026-53412
9.8 CRITICAL

Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user …

Jul 16, 2026
CVE-2026-53411
7.8 HIGH

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user …

Jul 16, 2026
CVE-2026-45368

Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the underlying URL methods for the KirbyTags and image blocks components …

Jul 16, 2026
CVE-2026-45334

Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the content-locking feature returned lock information without checking the requesting user's …

Jul 16, 2026
CVE-2026-44180
9.8 CRITICAL

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Versions 2.0.0rc1 and above prior to 3.3.0 …

Jul 16, 2026
CVE-2026-44177

Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correctly validate the provided user ID, …

Jul 16, 2026
CVE-2026-44176

Kirby is an open-source content management system. Versions prior to 4.9.1 and 5.4.1 do not check the `pages.access` permission during page draft rendering. Permissions are …

Jul 16, 2026
CVE-2026-44175

Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, Kirby did not securely sanitize the contents of the list field …

Jul 16, 2026
CVE-2026-44174

Kirby is an open-source content management system. Prior to 4.9.1 and 5.4.1, Kirby did not validate the model attributes that were used in its collection …

Jul 16, 2026
CVE-2026-14782
4.9 MEDIUM

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up …

Jul 16, 2026
CVE-2026-13713
6.2 MEDIUM

YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack. In the …

Jul 16, 2026
CVE-2026-61378
5.5 MEDIUM

A divide-by-zero vulnerability in the Productivity Suite allows a local attacker to cause a division by zero leading to a system crash.

Jul 16, 2026
CVE-2026-60073
5.9 MEDIUM

An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB device. This can lead …

Jul 16, 2026
CVE-2026-57896
6.1 MEDIUM

An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCTL request. This could …

Jul 16, 2026
CVE-2026-55173
8.1 HIGH

WWBN AVideo is an open source video platform. Versions 29.0 and below remain vulnerable to OS command injection because the fix for CVE-2026-33482 was incomplete …

Jul 16, 2026
CVE-2026-53410
7.0 HIGH

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user …

Jul 16, 2026
CVE-2026-53409
7.8 HIGH

Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local access.

Jul 16, 2026
CVE-2026-44023
8.6 HIGH

Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.5.0 and above, prior to 2.74.1, docling-core did not …

Jul 16, 2026
CVE-2026-44019
8.1 HIGH

Docling Core defines core data types and transformations for the document processing application Docling. In versions 2.5.0 and above, prior to 2.74.1, docling-core could allow …

Jul 16, 2026
CVE-2026-38158
9.8 CRITICAL

A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL statements.

Jul 16, 2026
CVE-2026-36425
6.5 MEDIUM

An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send process termination …

Jul 16, 2026
CVE-2026-33731
6.5 MEDIUM

WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/AuthorizeNet/webhook.php contains a signature verification bypass that …

Jul 16, 2026
CVE-2026-33692
7.5 HIGH

WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through the official Docker compose configuration. The …

Jul 16, 2026
CVE-2026-11889
6.5 MEDIUM

SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation attack that could allow an authorized attacker to …

Jul 16, 2026
CVE-2024-34268
7.1 HIGH

EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth connections. This vulnerability allows attackers …

Jul 16, 2026
CVE-2024-32389
3.5 LOW

Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the update URLs component.

Jul 16, 2026
CVE-2024-32387
5.7 MEDIUM

An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the community string component.

Jul 16, 2026
CVE-2024-32386
7.3 HIGH

Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the SNMP update mechanism.

Jul 16, 2026
CVE-2024-32385
4.3 MEDIUM

An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via a boardID and revisionID components

Jul 16, 2026
CVE-2026-63397
6.4 MEDIUM

remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL schema that is passed to genql to inject arbitrary JavaScript or TypeScript. …

Jul 16, 2026
CVE-2026-63089
9.3 CRITICAL

WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers to recover WireGuard …

Jul 16, 2026
CVE-2026-62994
3.7 LOW

CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreDNS zone can …

Jul 16, 2026
CVE-2026-62963

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidirectional WebSocket transport with uni_websocket.compression enabled enforced uni_websocket.message_size_limit against compressed wire-frame length in …

Jul 16, 2026
CVE-2026-62309
7.5 HIGH

CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin …

Jul 16, 2026
CVE-2026-62299
5.3 MEDIUM

CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an optional revert flag, and …

Jul 16, 2026
CVE-2026-62290
7.3 HIGH

cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing and using those certificates. From 1.18.0 …

Jul 16, 2026
CVE-2026-61718
5.4 MEDIUM

bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb web UI BiscuitMiddleware authorization bypass list included the /cache/ …

Jul 16, 2026
CVE-2026-61389
7.0 HIGH

An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL request, potentially resulting in …

Jul 16, 2026
CVE-2026-60140
6.1 MEDIUM

An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCTL request. This can …

Jul 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.