CVE Database

4091+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-7014
2.4 LOW

A flaw has been found in MaxSite CMS up to 109.3. This vulnerability affects unknown code of the component down_count Plugin. This manipulation of the …

Apr 26, 2026
CVE-2026-7013
2.4 LOW

A security vulnerability has been detected in MaxSite CMS up to 109.3. Affected by this issue is some unknown functionality of the component mail_send Plugin. …

Apr 26, 2026
CVE-2026-7012
2.4 LOW

A vulnerability was detected in MaxSite CMS up to 109.3. This affects an unknown part of the component Redirect Plugin. The manipulation of the argument …

Apr 26, 2026
CVE-2026-7011
2.4 LOW

A weakness has been identified in MaxSite CMS up to 109.3. Affected by this vulnerability is an unknown functionality of the file /admin/plugin_antispam of the …

Apr 26, 2026
CVE-2026-7001
2.4 LOW

A vulnerability was found in Datacom DM4100 1.3.6.1.4.1.3709. This affects an unknown part of the component Ethernet Configuration Page. Performing a manipulation of the argument …

Apr 25, 2026
CVE-2026-7000
2.4 LOW

A vulnerability has been found in Datacom DM4100 1.3.6.1.4.1.3709. Affected by this issue is some unknown functionality of the component VLAN Page. Such manipulation of …

Apr 25, 2026
CVE-2026-6999
2.4 LOW

A flaw has been found in BIVOCOM TR321 21.1.1.50. Affected by this vulnerability is an unknown functionality of the component Wireless Setting. This manipulation of …

Apr 25, 2026
CVE-2026-6998
2.4 LOW

A vulnerability was detected in BDCOM P3310D 0.4.2 10.1.0F Build 86345. Affected is an unknown function of the component New RMON Statistics Page. The manipulation …

Apr 25, 2026
CVE-2026-6997
2.4 LOW

A security vulnerability has been detected in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This impacts an unknown function of the component New RMON History Page. …

Apr 25, 2026
CVE-2026-6996
2.4 LOW

A weakness has been identified in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This affects an unknown function of the component rmon event Tab. Executing a …

Apr 25, 2026
CVE-2026-6995
2.4 LOW

A security flaw has been discovered in BDCOM P3310D 0.4.2 10.1.0F Build 86345. The impacted element is an unknown function of the file /index.asp of …

Apr 25, 2026
CVE-2026-6990
3.5 LOW

A vulnerability was found in projeto-siga siga 11.0.3.18. The affected element is an unknown function of the file /sigawf/app/responsavel/novo. Performing a manipulation of the argument …

Apr 25, 2026
CVE-2026-6986
3.7 LOW

A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This issue affects the function mg_aes_gcm_decrypt of the file /src/tls_aes128.c of the component …

Apr 25, 2026
CVE-2026-41488
3.1 LOW

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.1.14, langchain-openai's _url_to_size() helper (used by get_num_tokens_from_messages for image token counting) validated URLs …

Apr 24, 2026
CVE-2026-42040
3.7 LOW

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the encode() function in lib/helpers/AxiosURLSearchParams.js contains a character …

Apr 24, 2026
CVE-2026-41321
2.2 LOW

@astrojs/cloudflare is an SSR adapter for use with Cloudflare Workers targets. Prior to 13.1.10, the fetch() call for remote images in packages/integrations/cloudflare/src/utils/image-binding-transform.ts uses the default …

Apr 24, 2026
CVE-2026-31051
3.8 LOW

An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Client Balance component

Apr 24, 2026
CVE-2026-41357
3.3 LOW

OpenClaw before 2026.3.31 contains an environment variable leakage vulnerability in SSH-based sandbox backends that pass unsanitized process.env to child processes. Attackers can exploit this by …

Apr 23, 2026
CVE-2026-41354
3.7 LOW

OpenClaw before 2026.4.2 contains an insufficient scope vulnerability in Zalo webhook replay dedupe keys that allows legitimate events from different conversations or senders to collide. …

Apr 23, 2026
CVE-2026-41333
3.7 LOW

OpenClaw before 2026.3.31 contains an authentication rate limiting bypass vulnerability that allows attackers to circumvent shared authentication protections using fake device tokens. Attackers can exploit …

Apr 23, 2026
CVE-2026-2708
3.7 LOW

A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate …

Apr 23, 2026
CVE-2026-4512
3.5 LOW

The reCaptcha by WebDesignBy WordPress plugin before 2.0 does not sanitize or escape the Site Key setting before outputting it in a JavaScript string context …

Apr 23, 2026
CVE-2026-41988
3.2 LOW

uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID …

Apr 23, 2026
CVE-2026-1272
2.7 LOW

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user access control panel.

Apr 23, 2026
CVE-2026-34067
3.1 LOW

nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `HistoryTreeProof::verify` panics on a malformed proof where `history.len() != …

Apr 22, 2026
CVE-2026-3254
3.5 LOW

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user …

Apr 22, 2026
CVE-2026-35381
3.3 LOW

A logic error in the cut utility of uutils coreutils causes the utility to ignore the -s (only-delimited) flag when using the -z (null-terminated) and …

Apr 22, 2026
CVE-2026-35379
3.3 LOW

A logic error in the tr utility of uutils coreutils causes the program to incorrectly define the [:graph:] and [:print:] character classes. The implementation mistakenly …

Apr 22, 2026
CVE-2026-35378
3.3 LOW

A logic error in the expr utility of uutils coreutils causes the program to evaluate parenthesized subexpressions during the parsing phase rather than at the …

Apr 22, 2026
CVE-2026-35377
3.3 LOW

A logic error in the env utility of uutils coreutils causes a failure to correctly parse command-line arguments when utilizing the -S (split-string) option. In …

Apr 22, 2026
CVE-2026-35375
3.3 LOW

A logic error in the split utility of uutils coreutils causes the corruption of output filenames when provided with non-UTF-8 prefix or suffix inputs. The …

Apr 22, 2026
CVE-2026-35373
3.3 LOW

A logic error in the ln utility of uutils coreutils causes the program to reject source paths containing non-UTF-8 filename bytes when using target-directory forms …

Apr 22, 2026
CVE-2026-35371
3.3 LOW

The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly …

Apr 22, 2026
CVE-2026-35367
3.3 LOW

The nohup utility in uutils coreutils creates its default output file, nohup.out, without specifying explicit restricted permissions. This causes the file to inherit umask-based permissions, …

Apr 22, 2026
CVE-2026-35362
3.6 LOW

The safe_traversal module in uutils coreutils, which provides protection against Time-of-Check to Time-of-Use (TOCTOU) symlink races using file-descriptor-relative syscalls, is incorrectly limited to Linux targets. …

Apr 22, 2026
CVE-2026-35361
3.4 LOW

The mknod utility in uutils coreutils fails to handle security labels atomically by creating device nodes before setting the SELinux context. If labeling fails, the …

Apr 22, 2026
CVE-2026-35353
3.3 LOW

The mkdir utility in uutils coreutils incorrectly applies permissions when using the -m flag by creating a directory with umask-derived permissions (typically 0755) before subsequently …

Apr 22, 2026
CVE-2026-35346
3.3 LOW

The comm utility in uutils coreutils silently corrupts data by performing lossy UTF-8 conversion on all output lines. The implementation uses String::from_utf8_lossy(), which replaces invalid …

Apr 22, 2026
CVE-2026-35344
3.3 LOW

The dd utility in uutils coreutils suppresses errors during file truncation operations by unconditionally calling Result::ok() on truncation attempts. While intended to mimic GNU behavior …

Apr 22, 2026
CVE-2026-35343
3.3 LOW

The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is specified as the delimiter. The implementation fails to …

Apr 22, 2026
CVE-2026-35342
3.3 LOW

The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR …

Apr 22, 2026
CVE-2025-9957
2.7 LOW

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain …

Apr 22, 2026
CVE-2026-33599
3.1 LOW

A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) option to …

Apr 22, 2026
CVE-2026-33597
3.7 LOW

PRSD detection denial of service

Apr 22, 2026
CVE-2026-33596
3.1 LOW

A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of …

Apr 22, 2026
CVE-2026-6842
2.5 LOW

A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for …

Apr 22, 2026
CVE-2026-22746
3.7 LOW

Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then DaoAuthenticationProvider's …

Apr 22, 2026
CVE-2026-6416
2.7 LOW

Tanium addressed an uncontrolled resource consumption vulnerability in Interact.

Apr 22, 2026
CVE-2026-6408
2.7 LOW

Tanium addressed an information disclosure vulnerability in Tanium Server.

Apr 22, 2026
CVE-2026-6392
2.7 LOW

Tanium addressed an information disclosure vulnerability in Threat Response.

Apr 22, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.