CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-77507
5.3 MEDIUM

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, Weblate's object-scoped RSS feeds do not apply the …

Aug 26, 2026
CVE-2026-75364
6.8 MEDIUM

Comfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build), the update_interface_png SET handler in /usr/bin/webmgnt fails to sanitize the display_name parameter. User-controlled input is concatenated via …

Aug 26, 2026
CVE-2026-75363
6.8 MEDIUM

An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute arbitrary code via the /usr/bin/webmgnt, /cgi-bin/mbox-config, and the parameters timestr, display_n.

Aug 26, 2026
CVE-2026-62326
6.5 MEDIUM

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a user with the built-in "Edit source" role …

Aug 26, 2026
CVE-2026-62249
4.3 MEDIUM

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, an authenticated user with access to a project …

Aug 26, 2026
CVE-2026-61790
4.4 MEDIUM

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a team can require its members to configure …

Aug 26, 2026
CVE-2026-55227
4.3 MEDIUM

Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally scoped manner rather than restricting the …

Aug 26, 2026
CVE-2026-52473
4.3 MEDIUM

An issue in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the content parameter is directly concatenated to the ProcessBuilder.

Aug 26, 2026
CVE-2026-39275
6.1 MEDIUM

Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code via the item.php, field-select.js and tags.js components

Aug 26, 2026
CVE-2026-79939
5.8 MEDIUM

Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially …

Aug 26, 2026
CVE-2026-75601
4.3 MEDIUM

Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instances with both basic-auth and metrics features …

Aug 26, 2026
CVE-2026-74774
5.9 MEDIUM

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading …

Aug 26, 2026
CVE-2026-74771
6.5 MEDIUM

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit …

Aug 26, 2026
CVE-2026-71172
4.3 MEDIUM

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit …

Aug 26, 2026
CVE-2026-71054
6.5 MEDIUM

Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily exploitable vulnerability allows unauthenticated attacker with network …

Aug 26, 2026
CVE-2026-67275
5.3 MEDIUM

Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerability. An unauthenticated attacker with remote access could potentially exploit this …

Aug 26, 2026
CVE-2026-49809
6.5 MEDIUM

Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low …

Aug 26, 2026
CVE-2026-47848
6.1 MEDIUM

In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client may leak credentials. In order for this to happen, …

Aug 26, 2026
CVE-2026-47844
5.3 MEDIUM

In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for this to happen, the server must be …

Aug 26, 2026
CVE-2026-47842
6.5 MEDIUM

Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as the encryption mode encrypt data with AES/CBC using …

Aug 26, 2026
CVE-2026-47834
4.8 MEDIUM

Spring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from untrusted sources. Spring Data JPA 4.1.0 Spring Data JPA …

Aug 26, 2026
CVE-2026-46371
6.5 MEDIUM

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) …

Aug 26, 2026
CVE-2026-46370
6.5 MEDIUM

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an …

Aug 26, 2026
CVE-2025-70340
6.5 MEDIUM

A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms comments functionality. An authenticated customer user can manipulate …

Aug 26, 2026
CVE-2026-79940
5.9 MEDIUM

Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Control vulnerability. An unauthenticated attacker with remote access …

Aug 26, 2026
CVE-2026-75466
6.5 MEDIUM

libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexed-color PNG image with a non-gray palette through tj3LoadImage12() or …

Aug 26, 2026
CVE-2026-63179
4.9 MEDIUM

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, authenticated backend users can disclose …

Aug 26, 2026
CVE-2026-48786
6.5 MEDIUM

Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/targets) returned unmasked team enroll …

Aug 26, 2026
CVE-2026-41262
4.3 MEDIUM

Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read endpoint (GET /api/latest/fleet/policies/{policy_id}) fails to verify …

Aug 26, 2026
CVE-2026-54256
5.4 MEDIUM

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend FileUpload form widget …

Aug 26, 2026
CVE-2026-47837
6.8 MEDIUM

Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This …

Aug 26, 2026
CVE-2026-32639
6.8 MEDIUM

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor …

Aug 26, 2026
CVE-2026-32593
5.9 MEDIUM

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is …

Aug 26, 2026
CVE-2026-81034
6.5 MEDIUM

Netmaker disables certificate verification on the connection to the configured mail server. The sender in pro/email/smtp.go assigns a TLS configuration whose skip-verify field is set …

Aug 26, 2026
CVE-2026-81033
5.3 MEDIUM

Automatisch reveals whether an address is registered through the response to its forgot-password request. The controller at packages/backend/src/controllers/internal/api/v1/users/forgot-password.js looks the address up and chains a …

Aug 26, 2026
CVE-2026-81030
6.5 MEDIUM

Mage AI does not confine the paths accepted by its browser-items API to the project directory. BrowserItemResource in mage_ai/api/resources/BrowserItemResource.py passes a caller-supplied path to the …

Aug 26, 2026
CVE-2026-81028
4.9 MEDIUM

ZLMediaKit confines the downloadFile API to a configured set of root directories with a prefix comparison that does not account for directory boundaries. The configuration …

Aug 26, 2026
CVE-2026-54614
4.3 MEDIUM

DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feature in src/Controller/MailPreviewController.php accepts a route-controlled previewName value in …

Aug 26, 2026
CVE-2026-48549
6.5 MEDIUM

Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSRF vulnerability in cmd.cgi. When no Cookie header is present, the double-submit cookie protection …

Aug 26, 2026
CVE-2026-48548
6.5 MEDIUM

Nagios Core before 4.5.12 contains a cross-site request forgery vulnerability in cmd.cgi where the CSRF protection mechanism passes validation when the NagFormId cookie is absent. …

Aug 26, 2026
CVE-2026-54553
5.4 MEDIUM

Starlette-Admin is a fast, beautiful and extensible administrative interface framework for FastAPI and Starlette applications. Prior to 0.16.1, the list API does not validate user-supplied …

Aug 26, 2026
CVE-2026-13481
5.4 MEDIUM

The IEEE 1588 PTP management-message parser in subsys/net/lib/ptp/tlv.c mishandles the PTP_MGMT_TIME management id. In tlv_mgmt_post_recv(), the PTP_MGMT_TIME case casts mgmt_tlv->data to a 10-byte struct ptp_timestamp …

Aug 26, 2026
CVE-2026-79902
5.5 MEDIUM

A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array …

Aug 26, 2026
CVE-2026-77801
6.5 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain …

Aug 26, 2026
CVE-2026-73102
5.7 MEDIUM

RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnerability in the macOS clipboard file-paste code path. The application accepts peer-supplied file descriptor names and …

Aug 26, 2026
CVE-2026-3035
5.5 MEDIUM

GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain …

Aug 26, 2026
CVE-2026-15387
4.3 MEDIUM

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain …

Aug 26, 2026
CVE-2025-10903
6.5 MEDIUM

GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain …

Aug 26, 2026
CVE-2026-80206
5.9 MEDIUM

NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep_node_action function compiles user-supplied regular expressions embedded in …

Aug 26, 2026
CVE-2026-80204
5.4 MEDIUM

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18 does not apply the API-key scope cap in the injectSecurityTab() function of BlueprintController when deciding whether a page's …

Aug 26, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.