CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-82594
5.0 MEDIUM

A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the component Annotation Processing. Such manipulation leads to …

Aug 31, 2026
CVE-2026-82591
5.3 MEDIUM

A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the function MD5Importer::MakeDataUnique of the file …

Aug 30, 2026
CVE-2026-82590
4.3 MEDIUM

A weakness has been identified in Open5GS up to 2.7.7. The affected element is the function smf_nudm_sdm_handle_get of the file src/smf/nudm-handler.c of the component SMF. …

Aug 30, 2026
CVE-2026-82589
4.3 MEDIUM

A security flaw has been discovered in Open5GS up to 2.7.7. Impacted is the function amf_namf_comm_handle_n1_n2_message_transfer of the file src/amf/namf-handler.c of the component N1-N2 Message …

Aug 30, 2026
CVE-2026-82588
4.3 MEDIUM

A vulnerability was identified in Open5GS up to 2.7.7. This issue affects some unknown processing of the file src/amf/namf-handler.c of the component Transfer Endpoint. Such …

Aug 30, 2026
CVE-2026-82587
4.3 MEDIUM

A vulnerability was determined in Open5GS up to 2.7.7. This vulnerability affects the function amf_namf_comm_decode_ue_mm_context_list of the file src/amf/namf-handler.c of the component AMF. This manipulation …

Aug 30, 2026
CVE-2026-82556
6.3 MEDIUM

A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migrations/allowlist/is_migrate_allowed.go of the component Repository Migration Handler. …

Aug 30, 2026
CVE-2026-82554
4.3 MEDIUM

A flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part of the file /api/add_customer.php. This manipulation of the argument …

Aug 30, 2026
CVE-2026-82553
6.3 MEDIUM

A vulnerability was detected in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected by this issue is the function mysqli_query of the file student_dashboard.php of …

Aug 30, 2026
CVE-2026-82552
4.3 MEDIUM

A security vulnerability has been detected in Linux Foundation Magma 1.9.0. Affected by this vulnerability is an unknown functionality of the file tasks/ngap/ngap_amf.c of the …

Aug 30, 2026
CVE-2026-82551
5.3 MEDIUM

A weakness has been identified in Linux Foundation Magma 1.9.0. Affected is an unknown function of the file ngap_amf_handlers.c of the component NGSetup Handler. Executing …

Aug 30, 2026
CVE-2026-82550
5.3 MEDIUM

A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component NGSetupRequest Handler. Performing a manipulation of …

Aug 30, 2026
CVE-2026-82658
4.3 MEDIUM

Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user's future role memberships. Attackers …

Aug 30, 2026
CVE-2026-82652
5.3 MEDIUM

SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible …

Aug 30, 2026
CVE-2026-82651
4.9 MEDIUM

SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path and /repo/diff/*path endpoints in kernel/server/serve.go. These routes require admin authentication …

Aug 30, 2026
CVE-2026-82650
4.4 MEDIUM

SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the RenderTemplate function (kernel/model/template.go), reachable via the POST /api/template/render endpoint (kernel/api/template.go). The endpoint …

Aug 30, 2026
CVE-2026-82647
6.1 MEDIUM

WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site's contact address by bypassing origin …

Aug 30, 2026
CVE-2026-82646
6.1 MEDIUM

WWBN AVideo contains an unauthenticated reflected cross-site scripting vulnerability in the url2Embed.json.php endpoint that allows attackers to inject malicious scripts by supplying URLs with HTML …

Aug 30, 2026
CVE-2026-82643
6.5 MEDIUM

WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php that accepts credentials over GET without rate limiting. Attackers can submit correct credentials repeatedly to …

Aug 30, 2026
CVE-2026-82548
5.3 MEDIUM

A vulnerability was determined in Linux Foundation Magma 1.9.0. The impacted element is an unknown function of the component InitialUEMessage Handler. This manipulation causes information …

Aug 30, 2026
CVE-2026-82547
6.5 MEDIUM

A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks/amf/amf_fsm.cpp of the component Registration Complete …

Aug 30, 2026
CVE-2026-82545
6.3 MEDIUM

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/sup_searchfrm.php. The manipulation of the …

Aug 30, 2026
CVE-2026-82640
5.5 MEDIUM

browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to …

Aug 30, 2026
CVE-2026-82637
5.3 MEDIUM

browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute …

Aug 30, 2026
CVE-2026-82544
4.3 MEDIUM

A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/views/gym.py of the component Password …

Aug 30, 2026
CVE-2026-82634
6.5 MEDIUM

Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that allows low-privileged users to render arbitrary Jinja templates by supplying raw template …

Aug 30, 2026
CVE-2026-82633
4.3 MEDIUM

Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpoint, allowing authenticated users to retrieve group memberships of …

Aug 30, 2026
CVE-2026-82541
6.3 MEDIUM

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_edit.php. …

Aug 30, 2026
CVE-2026-82540
6.3 MEDIUM

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/cust_searchfrm.php. The manipulation of the argument …

Aug 30, 2026
CVE-2026-82487
6.3 MEDIUM

A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affects an unknown part. Executing a manipulation can lead to weak password recovery. The attack can …

Aug 30, 2026
CVE-2026-82486
5.0 MEDIUM

A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the component Agent Installation Workflow. Performing a manipulation …

Aug 30, 2026
CVE-2026-82485
6.3 MEDIUM

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/pro_edit.php. Such …

Aug 30, 2026
CVE-2026-82484
6.3 MEDIUM

A flaw has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/emp_searchfrm.php. This manipulation of the …

Aug 30, 2026
CVE-2026-81766
6.6 MEDIUM

The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 …

Aug 30, 2026
CVE-2026-14835
6.8 MEDIUM

The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from …

Aug 30, 2026
CVE-2026-82479
6.3 MEDIUM

A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. …

Aug 30, 2026
CVE-2026-82417
5.3 MEDIUM

### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by …

Aug 30, 2026
CVE-2026-82424
6.3 MEDIUM

A weakness has been identified in PHPGurukul Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /student_edit1.php. Executing a …

Aug 29, 2026
CVE-2026-82423
5.4 MEDIUM

A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component …

Aug 29, 2026
CVE-2026-82422
6.3 MEDIUM

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/emp_del.php. The manipulation of …

Aug 29, 2026
CVE-2026-82421
6.3 MEDIUM

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/emp_edit.php. The manipulation of the …

Aug 29, 2026
CVE-2026-82476
5.3 MEDIUM

Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata fetcher, allowing unauthenticated attackers to bypass IP validation. Attackers …

Aug 29, 2026
CVE-2026-82470
5.4 MEDIUM

Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted code timestamp. Attackers who …

Aug 29, 2026
CVE-2026-82469
5.4 MEDIUM

Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can …

Aug 29, 2026
CVE-2026-82468
4.7 MEDIUM

Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with …

Aug 29, 2026
CVE-2026-82467
4.7 MEDIUM

Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers can craft paths with leading double slashes that browsers …

Aug 29, 2026
CVE-2026-82465
5.3 MEDIUM

pac4j-saml before 6.5.6 does not require signature validation of SAML LogoutRequest messages in SAML2LogoutValidator.validateLogoutRequest(). When an IdP sends no SessionIndex, a session can be destroyed …

Aug 29, 2026
CVE-2026-82464
6.1 MEDIUM

pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform() that accepts backslash-prefixed logout redirect targets matching logoutUrlPattern. Attackers can craft logout links with backslash-prefixed …

Aug 29, 2026
CVE-2026-82462
6.5 MEDIUM

pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token validation. Attackers can substitute access tokens minted for …

Aug 29, 2026
CVE-2026-82477
5.8 MEDIUM

In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. …

Aug 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.