CVE Database

4627+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-13573
3.3 LOW

A vulnerability was found in llvm llvm-project up to 22.1.6. This affects the function llvm::StringMap::insert in the library /lib/IR/ValueSymbolTable.cpp of the component ValueSymbolTable Module. The …

Jun 29, 2026
CVE-2026-13570
3.5 LOW

A vulnerability was detected in SourceCodester Inventory Management System 1.0. Impacted is an unknown function of the file /api/users_handler.php of the component User Registration Endpoint. …

Jun 29, 2026
CVE-2026-13558
3.5 LOW

A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown processing of the file /report/addreport of the component …

Jun 29, 2026
CVE-2025-0824
3.7 LOW

Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28. This issue affects Hitachi Virtual Storage Platform …

Jun 29, 2026
CVE-2026-13523
3.3 LOW

A weakness has been identified in GPAC up to 26.02.0. This affects an unknown part of the file src/utils/base_encoding.c of the component ISOBMFF Parser. Executing …

Jun 29, 2026
CVE-2026-13514
2.4 LOW

A weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android. This issue affects some unknown processing of the file …

Jun 29, 2026
CVE-2026-13511
3.1 LOW

A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversation of the file packages/server-core/src/handlers/memory.handlers.ts of the component Memory …

Jun 28, 2026
CVE-2026-13510
3.7 LOW

A vulnerability was found in SimStudioAI sim up to 0.6.92. Affected by this vulnerability is an unknown functionality in the library apps/sim/lib/core/security/deployment.ts of the component …

Jun 28, 2026
CVE-2026-13504
3.5 LOW

A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the component Mail Compose …

Jun 28, 2026
CVE-2026-13493
3.1 LOW

A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown processing of the file backend/controller/conversation_api.py of the component Workflow …

Jun 28, 2026
CVE-2026-13491
3.7 LOW

A vulnerability was detected in 78 xiaozhi-esp32 up to 2.2.6. This vulnerability affects the function Application::GetInstance of the file main/protocols/mqtt_protocol.cc of the component MQTT Goodbye …

Jun 28, 2026
CVE-2026-13490
3.7 LOW

A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document::canViewFile of the file front/document.send.php of the component Document Handler. Such …

Jun 28, 2026
CVE-2026-13489
3.1 LOW

A weakness has been identified in 78 xiaozhi-esp32 up to 2.2.6. Affected by this issue is the function ParseMessage of the file main/mcp_server.cc of the …

Jun 28, 2026
CVE-2026-13483
3.1 LOW

A flaw has been found in arc53 DocsGPT up to 0.18.0. The affected element is the function encrypt_credentials of the file application/security/encryption.py of the component …

Jun 28, 2026
CVE-2026-13482
3.7 LOW

A vulnerability was detected in skypilot-org skypilot up to 0.12.0. Impacted is the function username.encode of the file sky/users/server.py of the component User ID Handler. …

Jun 28, 2026
CVE-2026-58052
3.3 LOW

7-Zip for Windows through 26.02 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supplied Zone.Identifier stream …

Jun 28, 2026
CVE-2026-3472
3.5 LOW

Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, …

Jun 26, 2026
CVE-2026-57926
2.6 LOW

In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

Jun 26, 2026
CVE-2026-57922
3.1 LOW

In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible

Jun 26, 2026
CVE-2026-48936
3.3 LOW

A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This …

Jun 26, 2026
CVE-2026-48935
3.3 LOW

A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. …

Jun 26, 2026
CVE-2026-13322
3.8 LOW

A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely until a newline character …

Jun 26, 2026
CVE-2026-57522
3.5 LOW

Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into event-integration templates without JSON encoding. When an organization has …

Jun 25, 2026
CVE-2026-48940
3.4 LOW

A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `<script>` tag; …

Jun 25, 2026
CVE-2026-57588
3.3 LOW

A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious …

Jun 25, 2026
CVE-2026-57234
2.6 LOW

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse option, which Nokogiri turns on …

Jun 25, 2026
CVE-2026-12755
2.7 LOW

Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce …

Jun 25, 2026
CVE-2026-42004
3.7 LOW

An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT …

Jun 25, 2026
CVE-2026-40208
3.7 LOW

An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame.

Jun 25, 2026
CVE-2026-40011
3.7 LOW

An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid …

Jun 25, 2026
CVE-2026-3176
3.1 LOW

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain …

Jun 25, 2026
CVE-2026-0934
3.8 LOW

GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain …

Jun 25, 2026
CVE-2026-8662
3.3 LOW

Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file paths via crafted …

Jun 25, 2026
CVE-2026-49979
2.7 LOW

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send-test-email endpoint accepts attacker-controlled smtpHost and smtpPort values …

Jun 24, 2026
CVE-2026-39894
2.9 LOW

Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent decimal formatting in rrdtool_function_update() can corrupt RRDtool metric …

Jun 24, 2026
CVE-2026-52796
3.5 LOW

Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic when rendering, resulting in denial …

Jun 24, 2026
CVE-2026-57288
3.7 LOW

Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication …

Jun 24, 2026
CVE-2026-56370
3.3 LOW

ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. Attackers can trigger access violations by specifying malformed …

Jun 24, 2026
CVE-2026-56368
3.7 LOW

ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can …

Jun 24, 2026
CVE-2026-10753
2.7 LOW

The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-privileged users who have …

Jun 24, 2026
CVE-2026-50268
1.9 LOW

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Encryption 4.0.0 through 4.1.0, configuring `encrypt:rsa:algorithm=OAEP` …

Jun 17, 2026
CVE-2026-12567
2.2 LOW

The github_workflows module constructs local directory paths from user-controlled repository names without validating for symlinks. A local attacker sharing the scan directory can plant a …

Jun 17, 2026
CVE-2026-12566
3.1 LOW

The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authentication endpoint without validation. An attacker in a man-in-the-middle …

Jun 17, 2026
CVE-2026-6733
3.7 LOW

Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto …

Jun 17, 2026
CVE-2026-39199
2.9 LOW

snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.

Jun 17, 2026
CVE-2026-11525
3.7 LOW

Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the …

Jun 17, 2026
CVE-2026-35068
3.5 LOW

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with …

Jun 17, 2026
CVE-2026-12458
3.1 LOW

Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Jun 17, 2026
CVE-2026-0057
3.3 LOW

In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a missing permission check. This …

Jun 17, 2026
CVE-2025-62340
3.1 LOW

HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions …

Jun 17, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.