CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-61684

FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse-call endpoints under /api/invoke/* authenticate only by verifying a JWT signed with INVOKE_TOKEN_SECRET, …

Jul 15, 2026
CVE-2026-61646

FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta5, FastGPT's shared SSRF guard validates only the initial request URL before handing the request to …

Jul 15, 2026
CVE-2026-61644
7.7 HIGH

FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, the POST /api/core/chat/record/getCollectionQuote endpoint authenticates the caller's chat and collection context, but the initialId …

Jul 15, 2026
CVE-2026-61613

Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled …

Jul 15, 2026
CVE-2026-60065
3.7 LOW

When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the …

Jul 15, 2026
CVE-2026-60062
6.4 MEDIUM

The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. The …

Jul 15, 2026
CVE-2026-59762
7.5 HIGH

When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Impact: System performance can degrade …

Jul 15, 2026
CVE-2026-56434
6.5 MEDIUM

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering …

Jul 15, 2026
CVE-2026-55723
8.3 HIGH

When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress …

Jul 15, 2026
CVE-2026-54563
7.1 HIGH

Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, a Cloudreve WebDAV account rooted at a configured folder can send paths such …

Jul 15, 2026
CVE-2026-54562
6.5 MEDIUM

Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, Cloudreve's remote download workflow accepts user-supplied URLs at POST /api/v4/workflow/download and passes them …

Jul 15, 2026
CVE-2026-54560
7.6 HIGH

Cloudreve is a self-hosted file management and sharing system. From 4.12.0 until 4.16.1, Cloudreve's OAuth access tokens are issued without the OAuth client_id claim, so …

Jul 15, 2026
CVE-2026-52865
6.5 MEDIUM

When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause …

Jul 15, 2026
CVE-2026-42533
8.1 HIGH

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex …

Jul 15, 2026
CVE-2026-33213
6.1 MEDIUM

Redash is a package for data visualization and sharing. From 5.0.2 to 26.3.0, the get_next_path() function in Redash's authentication module stripped the scheme and netloc …

Jul 15, 2026
CVE-2026-59838
5.9 MEDIUM

A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.2.0 through …

Jul 15, 2026
CVE-2026-43637
9.1 CRITICAL

Cornac before 2.6.0 contains a path traversal (Tar Slip) vulnerability that allows attackers to write arbitrary files outside the intended cache directory by supplying a …

Jul 15, 2026
CVE-2026-58559
6.5 MEDIUM

DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availability.

Jul 15, 2026
CVE-2026-58558
7.8 HIGH

Permission control vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jul 15, 2026
CVE-2026-58557
4.8 MEDIUM

Design defect vulnerability in Expedition mode. Impact: Successful exploitation of this vulnerability may affect availability.

Jul 15, 2026
CVE-2026-58556
5.1 MEDIUM

Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect availability.

Jul 15, 2026
CVE-2026-58555
6.6 MEDIUM

Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect availability.

Jul 15, 2026
CVE-2026-58554
6.6 MEDIUM

Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jul 15, 2026
CVE-2026-58553
4.0 MEDIUM

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jul 15, 2026
CVE-2026-58552
5.1 MEDIUM

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jul 15, 2026
CVE-2026-58551
5.1 MEDIUM

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jul 15, 2026
CVE-2026-58550
4.0 MEDIUM

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jul 15, 2026
CVE-2026-58549
4.0 MEDIUM

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jul 15, 2026
CVE-2026-46459

ICU Scandinavia Boomerang is vulnerable to a missing authentication flaw in its device receiver endpoints. This allows an unauthenticated remote attacker to read full facility …

Jul 15, 2026
CVE-2026-46458

ICU Scandinavia Boomerang is vulnerable to an information disclosure flaw where sensitive credential files are exposed via static HTTP. This allows an unauthenticated remote attacker …

Jul 15, 2026
CVE-2026-15809
7.8 HIGH

A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting …

Jul 15, 2026
CVE-2026-15779
6.1 MEDIUM

A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a …

Jul 15, 2026
CVE-2026-61873
8.1 HIGH

Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, which is validated against path traversal before Twig processing but …

Jul 15, 2026
CVE-2026-61872
2.5 LOW

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the TIFF encoder when an invalid tiff:tile-geometry is specified. Supplying malformed tile geometry parameters causes …

Jul 15, 2026
CVE-2026-61871
3.7 LOW

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file …

Jul 15, 2026
CVE-2026-61869
2.9 LOW

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the MIFF encoder that occurs when a memory allocation fails during MIFF image processing, which …

Jul 15, 2026
CVE-2026-61868
3.7 LOW

ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when opening of the blob fails. Repeated triggering …

Jul 15, 2026
CVE-2026-61867
2.9 LOW

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory allocation fails. Attackers can trigger allocation failures during TIFF image processing …

Jul 15, 2026
CVE-2026-61866
2.9 LOW

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by …

Jul 15, 2026
CVE-2026-61865
2.9 LOW

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation: when a specific operation fails, a small memory leak occurs.

Jul 15, 2026
CVE-2026-61864
2.9 LOW

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log colorspace: when the operation fails, a small amount of memory …

Jul 15, 2026
CVE-2026-61863
2.9 LOW

ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a temporary file cannot be created, resulting …

Jul 15, 2026
CVE-2026-61862
2.9 LOW

ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not …

Jul 15, 2026
CVE-2026-61860
3.7 LOW

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to use memory …

Jul 15, 2026
CVE-2026-61859
3.3 LOW

ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading …

Jul 15, 2026
CVE-2026-61464
1.8 LOW

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which can …

Jul 15, 2026
CVE-2026-61457
8.8 HIGH

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media controller. HandlesMediaUploads::validateFileExtension() inspects only the final file extension …

Jul 15, 2026
CVE-2026-61453
6.1 MEDIUM

Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detectXss()) runs on raw page content before Twig processing. When Twig …

Jul 15, 2026
CVE-2026-61452
5.3 MEDIUM

The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where JWT access tokens are issued without a jti (JWT ID) claim …

Jul 15, 2026
CVE-2026-61451
9.6 CRITICAL

The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoint. The sanitizeHttpUrl() function …

Jul 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.