CVE Database

9856+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-62415
9.1 CRITICAL

The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.

Jul 21, 2026
CVE-2026-13439
9.8 CRITICAL

The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This …

Jul 21, 2026
CVE-2026-64625
9.8 CRITICAL

AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. …

Jul 20, 2026
CVE-2026-52656
9.8 CRITICAL

An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary code via …

Jul 20, 2026
CVE-2024-51315
9.8 CRITICAL

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName

Jul 20, 2026
CVE-2024-51314
9.8 CRITICAL

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg.

Jul 20, 2026
CVE-2024-51312
9.8 CRITICAL

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg.

Jul 20, 2026
CVE-2026-53595
9.4 CRITICAL

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenController@userSetupSave`) selects …

Jul 20, 2026
CVE-2024-51313
9.8 CRITICAL

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg.

Jul 20, 2026
CVE-2024-51311
9.8 CRITICAL

The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList.

Jul 20, 2026
CVE-2026-63767
9.8 CRITICAL

ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle …

Jul 20, 2026
CVE-2026-63766
9.8 CRITICAL

GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into …

Jul 20, 2026
CVE-2026-44231
9.1 CRITICAL

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure …

Jul 20, 2026
CVE-2026-64193
9.8 CRITICAL

Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC …

Jul 20, 2026
CVE-2026-39878
9.3 CRITICAL

Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary …

Jul 20, 2026
CVE-2026-54051
9.9 CRITICAL

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAllowed`), which THREAT_MODEL.md calls the main …

Jul 20, 2026
CVE-2026-41252
9.8 CRITICAL

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when …

Jul 20, 2026
CVE-2026-35048
9.8 CRITICAL

The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper …

Jul 20, 2026
CVE-2026-51027
9.9 CRITICAL

An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.

Jul 20, 2026
CVE-2026-46412
10.0 CRITICAL

@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used …

Jul 20, 2026
CVE-2026-35198
9.0 CRITICAL

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member …

Jul 20, 2026
CVE-2026-63071
9.8 CRITICAL

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing …

Jul 20, 2026
CVE-2026-62183
9.8 CRITICAL

Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user workflow adapter is configured, …

Jul 20, 2026
CVE-2026-57308
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of …

Jul 20, 2026
CVE-2026-53421
9.8 CRITICAL

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on …

Jul 20, 2026
CVE-2026-53405
9.8 CRITICAL

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then …

Jul 20, 2026
CVE-2026-12701
9.0 CRITICAL

A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block …

Jul 20, 2026
CVE-2026-64620
9.8 CRITICAL

FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output buffer via …

Jul 20, 2026
CVE-2026-16242
9.4 CRITICAL

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), …

Jul 20, 2026
CVE-2026-16235
9.8 CRITICAL

Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for …

Jul 20, 2026
CVE-2026-13147
9.1 CRITICAL

The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP …

Jul 20, 2026
CVE-2026-44359
10.0 CRITICAL

Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs …

Jul 20, 2026
CVE-2026-64162
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init() In idpf_ptp_init(), read_dev_clk_lock is initialized after ptp_schedule_worker() had …

Jul 19, 2026
CVE-2026-64160
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential for tearing in ->remote_i_size and ->zero_point Fix potential tearing in using ->remote_i_size …

Jul 19, 2026
CVE-2026-64150
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: release local_lock before re-enabling softirqs Quoting sashiko: In the error path, local_bh_enable() is …

Jul 19, 2026
CVE-2026-64142
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ksmbd: close durable scavenger races against m_fp_list lookups ksmbd_durable_scavenger() has two related races against any …

Jul 19, 2026
CVE-2026-64136
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() Commit 96c4af418586 ("cifs: Fix locking usage for tcon …

Jul 19, 2026
CVE-2026-64132
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: refresh hdr pointer before ioam6_event() Reported by Sashiko: In ipv6_hop_ioam(), the hdr pointer …

Jul 19, 2026
CVE-2026-64125
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: keep RBUF EEE/PM disabled Setting RBUF_EEE_EN | RBUF_PM_EN in RBUF_ENERGY_CTRL breaks the RX …

Jul 19, 2026
CVE-2026-64122
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover mlx5e_tx_reporter_timeout_recover() accesses sq->netdev after mlx5e_safe_reopen_channels() has torn down and freed …

Jul 19, 2026
CVE-2026-64113
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA multicast source pruning ixgbevf_clean_rx_irq() prunes frames whose source MAC matches …

Jul 19, 2026
CVE-2026-64106
9.0 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits Userspace can restore an ITS Device …

Jul 19, 2026
CVE-2026-64102
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Reject MPA FPDU length underflow before signed receive math A malicious connected siw peer …

Jul 19, 2026
CVE-2026-64091
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix TOCTOU race for reported vlans The local TT based TVLV is generated …

Jul 19, 2026
CVE-2026-64089
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix negative last_changeset_len batadv_piv_tt::last_changeset_len len was declared as s16, but the field is …

Jul 19, 2026
CVE-2026-64080
9.3 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Snapshot notifier callbacks under lock Both notification handlers currently look up a notifier …

Jul 19, 2026
CVE-2026-64069
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix cancellation of a DIO and single read subrequests When the preparation of a …

Jul 19, 2026
CVE-2026-64068
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing locking around retry adding new subreqs Fix netfs_retry_read_subrequests() and netfs_retry_write_stream() to take …

Jul 19, 2026
CVE-2026-64067
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing barriers when accessing stream->subrequests locklessly The list of subrequests attached to stream->subrequests …

Jul 19, 2026
CVE-2026-64066
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_read_to_pagecache() to pause on subreq failure Fix netfs_read_to_pagecache() so that it pauses the …

Jul 19, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.