CVE Database

45217+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-86292
7.3 HIGH

A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown function of the file saveuser.php of the component User Creation. …

Sep 7, 2026
CVE-2026-86290
7.3 HIGH

A weakness has been identified in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /voting/ajax.php?action=save_category. This manipulation of the argument …

Sep 7, 2026
CVE-2026-86282
7.3 HIGH

A weakness has been identified in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected is an unknown function of the file travel/src/main/java/com/controller/CommonController.java of the component CommonDao. Executing …

Sep 7, 2026
CVE-2026-78254
7.4 HIGH

The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it …

Sep 7, 2026
CVE-2026-14296
7.5 HIGH

When using the Direct XIP update strategy, the main application image starts other cores (i.e. radio core), based on the currently active slot without additional …

Sep 7, 2026
CVE-2026-86277
7.3 HIGH

A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. Impacted is an unknown function of the file delete_exam.php. The manipulation …

Sep 7, 2026
CVE-2026-86276
7.3 HIGH

A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing …

Sep 7, 2026
CVE-2026-86273
7.3 HIGH

A weakness has been identified in projeto-siga siga up to 11.1.1. Affected by this issue is the function DownloadExterno.getUrl of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExUtilController.java of the …

Sep 7, 2026
CVE-2026-86272
7.3 HIGH

A vulnerability was determined in Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.6001.1096.1000. This impacts an unknown function of the file /Report/Upload/UploadFormImg.ashx. Executing a manipulation …

Sep 7, 2026
CVE-2026-86268
7.3 HIGH

A vulnerability was detected in itsourcecode School Management System 1.0. Impacted is an unknown function of the file User_Login.php. The manipulation of the argument email …

Sep 7, 2026
CVE-2026-86313
7.8 HIGH

Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.

Sep 7, 2026
CVE-2026-86263
7.3 HIGH

A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Cancellation. The …

Sep 7, 2026
CVE-2026-86262
7.3 HIGH

A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects the function updateOrderSta1/updateOrderdiseaseInfo of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order …

Sep 7, 2026
CVE-2026-86261
7.3 HIGH

A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The impacted element is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component …

Sep 7, 2026
CVE-2026-20502
8.4 HIGH

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Sep 7, 2026
CVE-2026-20501
8.4 HIGH

In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with …

Sep 7, 2026
CVE-2026-86225
7.3 HIGH

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The …

Sep 6, 2026
CVE-2026-86224
7.3 HIGH

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a manipulation of …

Sep 6, 2026
CVE-2026-86223
7.3 HIGH

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of the file /admin/modal_add_coursea.php. Performing a manipulation of …

Sep 6, 2026
CVE-2026-86222
7.3 HIGH

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. This affects the function mysqli_query of the file /admin/modal_add_course2.php. Such manipulation of …

Sep 6, 2026
CVE-2026-86221
7.3 HIGH

A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is the function mysqli_query of the file /admin/modal_add_course1.php. This …

Sep 6, 2026
CVE-2026-86220
7.3 HIGH

A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. The affected element is the function mysqli_query of the file /admin/modal_add_course.php. The manipulation …

Sep 6, 2026
CVE-2026-82209
8.2 HIGH

When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly …

Sep 6, 2026
CVE-2026-82208
7.5 HIGH

With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store after …

Sep 6, 2026
CVE-2026-80255
7.5 HIGH

A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store …

Sep 6, 2026
CVE-2026-80231
7.5 HIGH

A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store …

Sep 6, 2026
CVE-2026-80230
7.5 HIGH

When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning …

Sep 6, 2026
CVE-2026-80229
7.5 HIGH

When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated …

Sep 6, 2026
CVE-2026-13608
7.4 HIGH

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker …

Sep 6, 2026
CVE-2026-19633
8.8 HIGH

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted …

Sep 6, 2026
CVE-2026-86259
7.5 HIGH

OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider …

Sep 6, 2026
CVE-2026-86214
7.3 HIGH

A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causes improper authentication. …

Sep 6, 2026
CVE-2026-86213
7.3 HIGH

A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of the component Search Handler. The manipulation of …

Sep 6, 2026
CVE-2026-86250
7.5 HIGH

h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can send a crafted …

Sep 6, 2026
CVE-2026-86242
8.1 HIGH

Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled …

Sep 6, 2026
CVE-2022-51009
7.5 HIGH

PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with …

Sep 6, 2026
CVE-2026-86211
7.3 HIGH

A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulation …

Sep 6, 2026
CVE-2026-86210
7.3 HIGH

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Sep 6, 2026
CVE-2026-86209
7.3 HIGH

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_user.php. This manipulation of …

Sep 6, 2026
CVE-2026-86208
7.3 HIGH

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulation …

Sep 6, 2026
CVE-2026-86180
7.3 HIGH

A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php …

Sep 6, 2026
CVE-2026-84219
7.5 HIGH

The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store …

Sep 6, 2026
CVE-2026-18480
8.8 HIGH

The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, …

Sep 6, 2026
CVE-2026-86168
7.3 HIGH

A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation …

Sep 6, 2026
CVE-2026-86166
8.8 HIGH

A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing …

Sep 6, 2026
CVE-2026-86162
7.3 HIGH

A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument …

Sep 6, 2026
CVE-2026-86161
7.3 HIGH

A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a manipulation of …

Sep 6, 2026
CVE-2026-86160
7.3 HIGH

A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such manipulation of …

Sep 6, 2026
CVE-2026-86159
7.3 HIGH

A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument …

Sep 6, 2026
CVE-2026-18056
7.5 HIGH

The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is …

Sep 6, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.