CVE Database

45217+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-81270
7.5 HIGH

Apache Allura: exposure of non-public information via search. This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes …

Sep 4, 2026
CVE-2026-66840
7.5 HIGH

XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked.

Sep 4, 2026
CVE-2026-19224
7.2 HIGH

The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a …

Sep 4, 2026
CVE-2026-16281
7.1 HIGH

The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX …

Sep 4, 2026
CVE-2026-84715
8.8 HIGH

FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with …

Sep 2, 2026
CVE-2026-84485
7.5 HIGH

APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can …

Sep 2, 2026
CVE-2026-84484
7.5 HIGH

ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV …

Sep 2, 2026
CVE-2026-84702
7.5 HIGH

facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in …

Sep 2, 2026
CVE-2026-84700
8.6 HIGH

PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client …

Sep 2, 2026
CVE-2026-84696
8.2 HIGH

Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass …

Sep 2, 2026
CVE-2026-84695
8.7 HIGH

BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. …

Sep 2, 2026
CVE-2026-84694
8.8 HIGH

Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject shell …

Sep 2, 2026
CVE-2026-84482
8.8 HIGH

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins. Attackers …

Sep 1, 2026
CVE-2026-84478
7.3 HIGH

WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attackers to delete arbitrary .log files by supplying directory traversal …

Sep 1, 2026
CVE-2026-84476
7.5 HIGH

WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit(). Attackers can …

Sep 1, 2026
CVE-2026-84423
7.3 HIGH

A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file controllers/resource.go of the component upload-resource API. Such …

Sep 1, 2026
CVE-2026-84208
7.5 HIGH

AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin's regions.json.php and cities.json.php endpoints. The country and region GET parameters are …

Sep 1, 2026
CVE-2026-84375
7.5 HIGH

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources …

Sep 1, 2026
CVE-2026-84374
7.5 HIGH

Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method resolves the caller-controlled $destination supplied through …

Sep 1, 2026
CVE-2026-83549
7.8 HIGH KEV

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) …

Sep 1, 2026
CVE-2026-84370
8.2 HIGH

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, …

Sep 1, 2026
CVE-2026-84366
7.4 HIGH

Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request …

Sep 1, 2026
CVE-2026-73782
8.8 HIGH

A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability …

Sep 1, 2026
CVE-2026-73781
8.4 HIGH

A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an …

Sep 1, 2026
CVE-2026-73780
8.3 HIGH

A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow …

Sep 1, 2026
CVE-2026-73779
8.2 HIGH

Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful …

Sep 1, 2026
CVE-2026-73778
8.1 HIGH

A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a …

Sep 1, 2026
CVE-2026-73777
8.1 HIGH

Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls.

Sep 1, 2026
CVE-2026-73776
7.9 HIGH

A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful exploitation could allow an authenticated malicious actor with administrative privileges to …

Sep 1, 2026
CVE-2026-73775
7.7 HIGH

Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an …

Sep 1, 2026
CVE-2026-73774
7.6 HIGH

A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated disclosure of sensitive information by sending specially crafted …

Sep 1, 2026
CVE-2026-73773
7.5 HIGH

An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to interrupt the normal …

Sep 1, 2026
CVE-2026-73771
7.5 HIGH

An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability …

Sep 1, 2026
CVE-2026-73770
7.3 HIGH

An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor, under specific conditions outside the attacker's control and …

Sep 1, 2026
CVE-2026-73768
7.3 HIGH

A vulnerability exists in the command line interface of AOS-CX that may allow for improper processing of malformed input. Successful exploitation could result in the …

Sep 1, 2026
CVE-2026-73767
7.2 HIGH

Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands …

Sep 1, 2026
CVE-2026-73766
7.2 HIGH

Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with administrative privileges to inject arbitrary commands. Successful exploitation could …

Sep 1, 2026
CVE-2026-73765
7.2 HIGH

Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful exploitation of these vulnerabilities allows an attacker to write arbitrary files to the underlying …

Sep 1, 2026
CVE-2026-73764
7.1 HIGH

Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In …

Sep 1, 2026
CVE-2026-73763
7.1 HIGH

A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands. Successful exploitation could result in remote execution …

Sep 1, 2026
CVE-2026-73753
8.8 HIGH

Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system.

Sep 1, 2026
CVE-2026-73752
8.8 HIGH

An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files …

Sep 1, 2026
CVE-2026-73751
8.8 HIGH

An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.

Sep 1, 2026
CVE-2026-73750
8.8 HIGH

Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially …

Sep 1, 2026
CVE-2026-71981
8.8 HIGH

Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands by supplying a crafted PHP object …

Sep 1, 2026
CVE-2026-78592
7.3 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path …

Sep 1, 2026
CVE-2026-73725
7.0 HIGH

A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary …

Sep 1, 2026
CVE-2026-73724
7.1 HIGH

Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the …

Sep 1, 2026
CVE-2026-73723
7.1 HIGH

A privilege escalation vulnerability exists in the web-based management interface of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user …

Sep 1, 2026
CVE-2026-73722
7.2 HIGH

Command injection vulnerabilities in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated remote attacker to perform command injection against the …

Sep 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.