CVE Database

130945+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-85387

Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the state of the account the token …

Sep 16, 2026
CVE-2026-84397
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 16, 2026
CVE-2026-69147
6.5 MEDIUM

vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set media_io_kwargs.video.video_backend to …

Sep 16, 2026
CVE-2026-51990

An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component

Sep 16, 2026
CVE-2026-47094
8.8 HIGH

SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vulnerability that allows authenticated attackers to access and modify arbitrary employee records due to missing …

Sep 16, 2026
CVE-2026-18120

Concrete CMS before 9.5.3 exposed a legacy Express entry search endpoint that returned entry result JSON without invoking the canViewExpressEntries() permission check applied by the …

Sep 16, 2026
CVE-2026-92603
6.5 MEDIUM

ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete other users' messages and …

Sep 16, 2026
CVE-2026-92602
7.1 HIGH

TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController. Authenticated attackers can attach webhooks to other …

Sep 16, 2026
CVE-2026-92601
6.5 MEDIUM

Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission defaults to false and is not overridden by any action methods. Authenticated …

Sep 16, 2026
CVE-2026-92600
6.5 MEDIUM

Guns through 8.3.5 contains an information disclosure vulnerability in SysUserController where /sysUser/detail and /sysUser/page endpoints omit requiredPermission configuration, causing the permission interceptor to skip RBAC …

Sep 16, 2026
CVE-2026-92405
7.3 HIGH

A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element is an unknown function of the file /index.php. Such …

Sep 16, 2026
CVE-2026-92402
6.3 MEDIUM

A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This issue affects the function index of the file UserController.java of the component …

Sep 16, 2026
CVE-2026-92401
7.3 HIGH

A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects the function top.upstudy.crm.utils.LoginUserUtil.releaseUserIdFromCookie. The manipulation leads to improper authentication. The attack can …

Sep 16, 2026
CVE-2026-92399
7.3 HIGH

A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/utils/rmt_ws.c of the component WebSocket Handler. Executing a manipulation of …

Sep 16, 2026
CVE-2026-92398
9.1 CRITICAL

A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality of the file /etc/rg_config/admin of the component user_list_note Module. …

Sep 16, 2026
CVE-2026-87031

n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST /ccm/api/1.0/users, the add() method of concrete/src/Api/Controller/Users.php) did not perform a permission check …

Sep 16, 2026
CVE-2026-87028

Concrete CMS 9 through 9.5.3 did not confirm that a board InstanceItem submitted to the custom-slot preview endpoint belonged to the board instance the requesting …

Sep 16, 2026
CVE-2026-86359
8.5 HIGH

Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, …

Sep 16, 2026
CVE-2026-86358
6.5 MEDIUM

Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this …

Sep 16, 2026
CVE-2026-85756
7.5 HIGH

SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into the command used to run scp on …

Sep 16, 2026
CVE-2026-85732
4.7 MEDIUM

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute URL from a registry-controlled Link …

Sep 16, 2026
CVE-2026-85731
8.8 HIGH

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store …

Sep 16, 2026
CVE-2026-85386

Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload question. Plain XML uploads were validated by …

Sep 16, 2026
CVE-2026-85385

Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output encoding on the Dashboard user management …

Sep 16, 2026
CVE-2026-84993
6.5 MEDIUM

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to 6.6.16 and 7.1.7, the shared …

Sep 16, 2026
CVE-2026-76420
9.0 CRITICAL

A vulnerability in the internal configuration of the Apache JServ Protocol (AJP)&nbsp;connector for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to impersonate …

Sep 16, 2026
CVE-2026-71182
3.0 LOW

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local …

Sep 16, 2026
CVE-2026-71181
3.0 LOW

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local …

Sep 16, 2026
CVE-2026-71180
8.2 HIGH

Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this …

Sep 16, 2026
CVE-2026-71179
7.3 HIGH

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A …

Sep 16, 2026
CVE-2026-69200
3.7 LOW

node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to node-opcua-client 2.145.0, the internal fieldsToJson method in packages/node-opcua-client/source/alarms_and_conditions/client_alarm.ts directly assigns unsanitized field names …

Sep 16, 2026
CVE-2026-68904
7.0 HIGH

node-opcua is an OPC UA implementation for TypeScript and Node.js. From 2.0.0 until 2.170.0, node-opcua clients using the default keepSessionAlive setting can enter a repeated …

Sep 16, 2026
CVE-2026-59974
7.8 HIGH

Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.14.0, stanza.resources.common.unzip in stanza/resources/common.py passes …

Sep 16, 2026
CVE-2026-59944
6.1 MEDIUM

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass …

Sep 16, 2026
CVE-2026-57173
6.5 MEDIUM

vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v1/chat/completions calls AudioMediaIO.load_bytes or AudioMediaIO.load_file without …

Sep 16, 2026
CVE-2026-42784
7.4 HIGH

A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a …

Sep 16, 2026
CVE-2026-20331
9.6 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software …

Sep 16, 2026
CVE-2026-20307
9.9 CRITICAL

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system …

Sep 16, 2026
CVE-2026-20306
9.1 CRITICAL

A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying …

Sep 16, 2026
CVE-2026-20305
9.1 CRITICAL

A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying …

Sep 16, 2026
CVE-2026-20234
9.9 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) …

Sep 16, 2026
CVE-2026-92627

A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a …

Sep 16, 2026
CVE-2026-92626
7.5 HIGH

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may …

Sep 16, 2026
CVE-2026-92625
7.5 HIGH

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/restartService endpoint is reachable without authentication and invokes an …

Sep 16, 2026
CVE-2026-92615
6.6 MEDIUM

A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include InsecureSkipVerify, a custom CA bundle, …

Sep 16, 2026
CVE-2026-92397
9.1 CRITICAL

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. …

Sep 16, 2026
CVE-2026-92385
2.4 LOW

A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/update_category.php of the …

Sep 16, 2026
CVE-2026-90999

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a …

Sep 16, 2026
CVE-2026-76104
5.5 MEDIUM

Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A high privileged attacker with remote access …

Sep 16, 2026
CVE-2026-70416
10.0 CRITICAL

Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading …

Sep 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.