CVE Database

135497+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-11625
7.5 HIGH

Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is initialised before forking, or when the functional interface is …

Jun 26, 2026
CVE-2026-57881
9.8 CRITICAL

An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient length validation …

Jun 26, 2026
CVE-2026-57880
9.8 CRITICAL

An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking …

Jun 26, 2026
CVE-2026-57879
9.8 CRITICAL

An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking …

Jun 26, 2026
CVE-2026-57878
9.8 CRITICAL

An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking …

Jun 26, 2026
CVE-2026-57877
8.6 HIGH

An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper handling of externally …

Jun 26, 2026
CVE-2026-57876
7.5 HIGH

An unauthenticated out-of-bounds write vulnerability exists in onvif.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when …

Jun 26, 2026
CVE-2026-57875
7.5 HIGH

An unauthenticated NULL pointer dereference vulnerability exists in the HTTP request parsing logic of multiple CGI components in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. …

Jun 26, 2026
CVE-2026-57874
7.5 HIGH

An unauthenticated buffer overflow vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when …

Jun 26, 2026
CVE-2026-57873
7.5 HIGH

An unauthenticated NULL pointer dereference vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper validation of …

Jun 26, 2026
CVE-2026-57872
7.5 HIGH

An unauthenticated directory traversal vulnerability exists in get_fcont.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient validation of user-supplied …

Jun 26, 2026
CVE-2026-49486
7.5 HIGH

The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was …

Jun 26, 2026
CVE-2026-2053
8.3 HIGH

The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows …

Jun 26, 2026
CVE-2026-8380
6.5 MEDIUM

The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users with …

Jun 26, 2026
CVE-2026-10835
7.7 HIGH

The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one of its AJAX actions before using …

Jun 26, 2026
CVE-2026-10823
7.5 HIGH

The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and does not validate a user-supplied …

Jun 26, 2026
CVE-2025-10268
5.3 MEDIUM

The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to path traversal which makes it possible for the attacker …

Jun 26, 2026
CVE-2026-8797

An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed …

Jun 26, 2026
CVE-2026-8661
4.8 MEDIUM

Server-Side Cross-Site Scripting and Server-Side Request Forgery vulnerability in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin version 3.1.4 and earlier on Linux allows remote …

Jun 26, 2026
CVE-2026-50745
6.1 MEDIUM

A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, …

Jun 26, 2026
CVE-2026-50744
4.3 MEDIUM

A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID …

Jun 26, 2026
CVE-2026-50742
5.4 MEDIUM

A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names being displayed without …

Jun 26, 2026
CVE-2026-50741
8.8 HIGH

Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by …

Jun 26, 2026
CVE-2026-50740
5.4 MEDIUM

A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh …

Jun 26, 2026
CVE-2026-50739
4.3 MEDIUM

A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation of linking campaigns and trackers through the …

Jun 26, 2026
CVE-2026-48936
3.3 LOW

A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This …

Jun 26, 2026
CVE-2026-48935
3.3 LOW

A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. …

Jun 26, 2026
CVE-2026-48934
4.3 MEDIUM

A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js …

Jun 26, 2026
CVE-2026-48933
7.5 HIGH

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported …

Jun 26, 2026
CVE-2026-48930
9.8 CRITICAL

A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This …

Jun 26, 2026
CVE-2026-48928
5.4 MEDIUM

A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js …

Jun 26, 2026
CVE-2026-48619
7.5 HIGH

A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory …

Jun 26, 2026
CVE-2026-48618
6.5 MEDIUM

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and …

Jun 26, 2026
CVE-2026-48615
7.5 HIGH

A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, …

Jun 26, 2026
CVE-2026-13226
6.5 MEDIUM

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'after' parameter in all versions up …

Jun 26, 2026
CVE-2026-9222
8.1 HIGH

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow …

Jun 26, 2026
CVE-2026-9221
7.5 HIGH

The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating communications between the mobile client and …

Jun 26, 2026
CVE-2026-9220
7.5 HIGH

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initialization vectors. …

Jun 26, 2026
CVE-2026-9219
6.5 MEDIUM

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authentication before assignment. …

Jun 26, 2026
CVE-2026-43920

FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patcher maintenance endpoint in FOSSBilling was accessible without authentication, …

Jun 26, 2026
CVE-2026-13322
3.8 LOW

A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely until a newline character …

Jun 26, 2026
CVE-2026-13318
6.4 MEDIUM

A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-forward request to a VirtualMachineInstance (VMI), virt-api reads the …

Jun 26, 2026
CVE-2026-13218
4.2 MEDIUM

A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data to a launcher-rooted path using os.WriteFile and os.Chown without symlink …

Jun 26, 2026
CVE-2026-13083
6.9 MEDIUM

A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An attacker with …

Jun 26, 2026
CVE-2026-12993
6.5 MEDIUM

A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE declarations or enable FEATURE_SECURE_PROCESSING. …

Jun 26, 2026
CVE-2026-40941
6.5 MEDIUM

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed …

Jun 25, 2026
CVE-2026-40084
6.5 MEDIUM

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal through the Report format_file Parameter, causing …

Jun 25, 2026
CVE-2026-40083
7.2 HIGH

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through unsanitized unserialize+implode in managers.php. At line 756 …

Jun 25, 2026
CVE-2026-40082
5.4 MEDIUM

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regenerate_id() after login, leading to Session Fixation. session_regenerate_id() is …

Jun 25, 2026
CVE-2026-40080
6.1 MEDIUM

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Redirect through a substring check rather than …

Jun 25, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.