CVE Database

5195+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-55785
3.7 LOW

free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptographic authentication comparisons in internal/sbi/processor/ue_authentication.go with ordinary equality …

Aug 28, 2026
CVE-2026-77063
3.7 LOW

multer is a middleware for handling multipart/form-data in Node.js. When an application uses an asynchronous fileFilter together with the fileSize limit, a race condition in …

Aug 28, 2026
CVE-2026-13735
3.7 LOW

Zephyr's WireGuard implementation in subsys/net/lib/wireguard/wg_crypto.c mishandled keepalive packets. In wg_process_data_message(), any type-4 transport-data message whose payload was exactly 16 bytes (an empty plaintext plus a …

Aug 28, 2026
CVE-2026-82112
3.5 LOW

A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src/index.ts of the component …

Aug 28, 2026
CVE-2026-38093
3.3 LOW

file_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.10, is vulnerable to path traversal (CWE-22) in its Android implementation. The openFileStream() method in FileUtils.kt uses …

Aug 28, 2026
CVE-2026-82249
3.1 LOW

gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns to …

Aug 28, 2026
CVE-2026-82238
3.1 LOW

filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to write past the declared Upload-Length by sending …

Aug 28, 2026
CVE-2026-82237
3.1 LOW

filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cleanup). The share record is keyed by …

Aug 28, 2026
CVE-2026-82236
3.1 LOW

File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can …

Aug 28, 2026
CVE-2026-52681
3.1 LOW

Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the …

Aug 28, 2026
CVE-2026-42393
3.1 LOW

The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An …

Aug 28, 2026
CVE-2026-40204
3.1 LOW

None None None No publicly available exploits are known.

Aug 28, 2026
CVE-2026-40203
3.7 LOW

When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and …

Aug 28, 2026
CVE-2026-79615
2.7 LOW

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API …

Aug 28, 2026
CVE-2026-81848
3.5 LOW

A vulnerability was determined in cyberchitta scrapling-fetch-mcp up to 0.2.2. The impacted element is the function s_fetch_page/s_fetch_pattern of the file src/scrapling_fetch_mcp/_fetcher.py. Executing a manipulation can …

Aug 28, 2026
CVE-2026-81836
3.7 LOW

A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1. This vulnerability affects unknown code of the file src/integrations/claude-code/oauth.ts of the component OAuth Callback. The …

Aug 28, 2026
CVE-2026-59314
3.7 LOW

Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response splitting when the input is a malicious file name. …

Aug 27, 2026
CVE-2026-59306
3.1 LOW

Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream …

Aug 27, 2026
CVE-2026-59305
3.1 LOW

Partition interceptor may be improperly added while sending message. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 …

Aug 27, 2026
CVE-2026-59304
3.1 LOW

Improper caching of the original content type in Spring Cloud Stream Avro. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring …

Aug 27, 2026
CVE-2026-59303
3.1 LOW

Dynamic destination cache size is not properly bound in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring …

Aug 27, 2026
CVE-2026-59302
3.1 LOW

Potential for logging sensitive data in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 …

Aug 27, 2026
CVE-2026-59301
3.1 LOW

Potential for logging sensitive data in Spring Cloud Function Azure. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function …

Aug 27, 2026
CVE-2026-59300
3.1 LOW

Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function …

Aug 27, 2026
CVE-2026-59299
3.1 LOW

Composition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud …

Aug 27, 2026
CVE-2026-59298
3.1 LOW

Potential for improper filtering of HTTP headers in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud …

Aug 27, 2026
CVE-2026-59297
3.1 LOW

Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring …

Aug 27, 2026
CVE-2026-59292
3.2 LOW

PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${java.io.tmpdir}/spring-integration/metadata-store.properties with world-readable permissions. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - …

Aug 27, 2026
CVE-2026-59291
2.0 LOW

Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud …

Aug 27, 2026
CVE-2026-59277
3.7 LOW

Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders for constructing an InetAddressMatcher that classifies a given IP address as belonging to an internal (private) …

Aug 27, 2026
CVE-2026-54713
3.7 LOW

CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() generates identifiers for jobs with shouldBeUnique enabled from the job class, method, …

Aug 27, 2026
CVE-2026-81725
3.7 LOW

NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying malformed TEI …

Aug 27, 2026
CVE-2026-81723
3.7 LOW

NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read. Attackers can …

Aug 27, 2026
CVE-2026-81717
3.5 LOW

openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker …

Aug 27, 2026
CVE-2026-81715
3.3 LOW

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the --debug …

Aug 27, 2026
CVE-2026-81696
3.3 LOW

openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape …

Aug 27, 2026
CVE-2026-81695
3.3 LOW

openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files with malicious key_id containing …

Aug 27, 2026
CVE-2026-81694
3.3 LOW

openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenticated manifest) before printing them in the …

Aug 27, 2026
CVE-2026-81685
3.3 LOW

openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control characters and line separators into the irreversible-removal …

Aug 27, 2026
CVE-2026-81102
3.1 LOW

The Dash MCP server bound its listener to the loopback address but never checked the host a request named. src/mcp_server_dash.py constructed the server for its …

Aug 27, 2026
CVE-2025-62343
3.1 LOW

HCL IntelliOps Event Management (IEM) is affected by an Admin Session Concurrency Vulnerability. it may allows user sessions to remain active after logout or session …

Aug 27, 2026
CVE-2026-13416
3.5 LOW

The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the …

Aug 27, 2026
CVE-2026-21807
3.9 LOW

HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.

Aug 26, 2026
CVE-2025-62341
3.7 LOW

HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in certain …

Aug 26, 2026
CVE-2026-21809
3.9 LOW

HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an …

Aug 26, 2026
CVE-2026-77573
3.5 LOW

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, a user permitted to manage component repository URLs …

Aug 26, 2026
CVE-2026-77508
3.5 LOW

Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to …

Aug 26, 2026
CVE-2026-56547
3.5 LOW

The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler requires the Logon Name and Mail Address …

Aug 26, 2026
CVE-2026-47843
3.7 LOW

In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrectly reuse a previously configured DNS resolver. Reactor Netty 1.3.0 - …

Aug 26, 2026
CVE-2026-54548
3.3 LOW

kas is a setup tool for bitbake based projects. Prior to 5.4, internal SSH key setup triggered by SSH_PRIVATE_KEY or SSH_PRIVATE_KEY_FILE creates ~/.ssh/config when no …

Aug 26, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.