CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-59287
5.9 MEDIUM

Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket client with keepAlive enabled. Spring for GraphQL 2.0.0 - 2.0.4 Spring …

Aug 27, 2026
CVE-2026-59281
6.1 MEDIUM

Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then render field errors using the no-argument Errors.getFieldErrors() or …

Aug 27, 2026
CVE-2026-59276
5.9 MEDIUM

Several components in Spring Security compare security-sensitive values using standard string equality (String.equals()) rather than a constant-time comparison. Because String.equals() returns as soon as it …

Aug 27, 2026
CVE-2026-54732
6.5 MEDIUM

libreoffice-convert is a Node.js module for converting office documents to different formats. Prior to 1.8.2, index.js uses the caller-controlled options.fileName value in path.join(tempDir.name, fileName) without …

Aug 27, 2026
CVE-2026-37073
5.3 MEDIUM

Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to send emails from the configured SMPT server on the …

Aug 27, 2026
CVE-2026-37067
5.3 MEDIUM

Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a desired date forwards …

Aug 27, 2026
CVE-2026-37064
5.3 MEDIUM

User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to enumerate the application users via sending a specially crafted POST …

Aug 27, 2026
CVE-2026-37009
6.5 MEDIUM

A SQL injection vulnerability in NL2SQLTool in crewai-tools v1.10.2rc1 allows a remote attacker to execute arbitrary SQL commands via an unsanitized sql_query argument.

Aug 27, 2026
CVE-2026-34620
5.5 MEDIUM

DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds write vulnerability that could lead to application denial-of-service. An attacker could leverage this …

Aug 27, 2026
CVE-2026-34616
5.5 MEDIUM

DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this …

Aug 27, 2026
CVE-2026-25250
6.0 MEDIUM

EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot disable."

Aug 27, 2026
CVE-2026-18374
4.9 MEDIUM

Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 …

Aug 27, 2026
CVE-2026-81724
5.3 MEDIUM

NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure …

Aug 27, 2026
CVE-2026-81720
6.2 MEDIUM

openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to trigger out-of-memory conditions during key derivation. Attackers with …

Aug 27, 2026
CVE-2026-81716
5.2 MEDIUM

openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authorized file access using a bare string-prefix match. A sandboxed plugin …

Aug 27, 2026
CVE-2026-81706
6.8 MEDIUM

openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the …

Aug 27, 2026
CVE-2026-81703
5.5 MEDIUM

openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC …

Aug 27, 2026
CVE-2026-81697
5.5 MEDIUM

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative configuration file resolution flaw in crypt_settings.py, where CONFIG_FILE (originally the absolute per-user path ~/.crypt_settings.json) is …

Aug 27, 2026
CVE-2026-81687
5.5 MEDIUM

openssl_encrypt versions before 1.4.9 fail to enforce a time ceiling on key derivation function iteration counts specified in file metadata. Attackers can craft files with …

Aug 27, 2026
CVE-2026-81686
6.2 MEDIUM

openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set method performs neither a polkit authorization check nor value validation. Any local user …

Aug 27, 2026
CVE-2026-81684
6.2 MEDIUM

In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to the CLI child process on the command line via …

Aug 27, 2026
CVE-2026-81682
6.2 MEDIUM

openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes decrypted plaintext with world-readable default permissions. Attackers can read …

Aug 27, 2026
CVE-2026-81681
4.6 MEDIUM

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB Workspace' with AES-256-GCM encryption and write a marker declaring …

Aug 27, 2026
CVE-2026-81680
4.0 MEDIUM

openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can …

Aug 27, 2026
CVE-2026-81664
5.3 MEDIUM

The OpenFaaS gateway registers GET /system/telemetry in gateway/main.go and, when basic_auth is enabled, wraps each administrative /system/* handler in auth.DecorateWithBasicAuth. TelemetryHandler was left out of …

Aug 27, 2026
CVE-2026-81334
6.1 MEDIUM

darknet subscripts its layer array with an index taken from a configuration file without checking it against the array's length. The array is allocated in …

Aug 27, 2026
CVE-2026-81101
6.5 MEDIUM

The configure command accepted any endpoint URL and stored it beside the user's access token. ConfigureCommand.execute in src/cli.ts persisted the value given to its endpoint …

Aug 27, 2026
CVE-2026-81100
6.8 MEDIUM

tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the …

Aug 27, 2026
CVE-2026-81099
6.8 MEDIUM

tiger-slack started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. mcp/src/httpServer.ts called the shared httpServerFactory helper and never set the …

Aug 27, 2026
CVE-2026-81095
6.8 MEDIUM

pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the …

Aug 27, 2026
CVE-2026-81092
6.8 MEDIUM

mcp-go accepted requests on its HTTP transports without checking the Host header. StreamableHTTPServer.ServeHTTP in server/streamable_http.go and SSEServer.ServeHTTP in server/sse.go served any request arriving over a …

Aug 27, 2026
CVE-2026-80213
4.0 MEDIUM

An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::MessageEncoder wrote a DNS label's length into a single octet without checking its …

Aug 27, 2026
CVE-2026-80211
5.9 MEDIUM

FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin/users.php passes md5($_POST['password']) to add_user() and update_user_password(), admin/change_current_user_password.php does the same when a …

Aug 27, 2026
CVE-2026-80210
6.5 MEDIUM

FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the _token hidden field in every form it renders, but …

Aug 27, 2026
CVE-2026-80209
4.3 MEDIUM

The updateWorkspace handler in mods/identity/src/workspaces/createUpdateWorkspace.ts in Fonoster through 0.22.7 invokes the gRPC callback with PERMISSION_DENIED when createIsWorkspaceMember reports that the caller is not a member …

Aug 27, 2026
CVE-2026-80207
5.3 MEDIUM

APITable through 1.13.0-beta.1 annotates the create handler of InternalNotifyController with requiredLogin = false. ResourceInterceptor honours that annotation by returning before any session or API key …

Aug 27, 2026
CVE-2026-79720
5.0 MEDIUM

Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse …

Aug 27, 2026
CVE-2026-75573
4.4 MEDIUM

In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI …

Aug 27, 2026
CVE-2026-75159
5.9 MEDIUM

An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication …

Aug 27, 2026
CVE-2026-71402
5.4 MEDIUM

An out-of-bounds read was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capture.c reports the IP total length as the payload length …

Aug 27, 2026
CVE-2026-5738
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in BilPark Informatics Technologies Industry and Trade Inc. DoXBASE allows Cross Zone Scripting. This …

Aug 27, 2026
CVE-2026-59280
4.3 MEDIUM

Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input …

Aug 27, 2026
CVE-2026-59272
6.8 MEDIUM

Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log …

Aug 27, 2026
CVE-2026-40526
6.5 MEDIUM

Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying absolute filesystem paths to the GET …

Aug 27, 2026
CVE-2026-19854
6.1 MEDIUM

When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connection library ignores that and …

Aug 27, 2026
CVE-2026-11754
5.3 MEDIUM

Observable discrepancy vulnerability in Seres Software syWEB allows Account Footprinting. This issue affects syWEB: through 27082026. NOTE: The vendor was contacted and it was learned …

Aug 27, 2026
CVE-2026-11747
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Seres Software syWEB allows Reflected XSS. This issue affects syWEB: through 27082026. NOTE: …

Aug 27, 2026
CVE-2025-62342
6.4 MEDIUM

HCL IntelliOps Event Management (IEM) is affected by a Session Deletion Vulnerability. It may allow improper handling of user sessions, resulting in sessions not being …

Aug 27, 2026
CVE-2026-81668
5.4 MEDIUM

A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the parent Content View Filter. An …

Aug 27, 2026
CVE-2026-81658
6.5 MEDIUM

A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving an audited template revision. An authenticated, low privileged …

Aug 27, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.