CVE Database

45217+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-61761
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61760
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61759
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61758
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61757
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61756
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61755
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61754
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61753
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61752
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61751
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61750
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-58567
8.8 HIGH

Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root …

Sep 1, 2026
CVE-2026-49329
7.5 HIGH

A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to golang.org/x/text/language.ParseAcceptLanguage() without input validation. A bypass …

Sep 1, 2026
CVE-2026-10195
8.8 HIGH

The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 8.0.1. This is due to insufficient input sanitization …

Sep 1, 2026
CVE-2026-84233
7.0 HIGH

A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated …

Sep 1, 2026
CVE-2026-84115
8.3 HIGH

A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT …

Sep 1, 2026
CVE-2026-84111
7.3 HIGH

A flaw has been found in Chanjet CRM up to 20260707. This issue affects some unknown processing of the file jxf_dump_table.php. This manipulation of the …

Sep 1, 2026
CVE-2026-79686
8.8 HIGH

Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain …

Sep 1, 2026
CVE-2026-58569
8.8 HIGH

Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute …

Sep 1, 2026
CVE-2026-18780
7.1 HIGH

Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Cross Site Request Forgery. This issue affects …

Sep 1, 2026
CVE-2026-18771
7.5 HIGH

Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass. This issue affects Talassoft …

Sep 1, 2026
CVE-2026-18630
8.8 HIGH

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software …

Sep 1, 2026
CVE-2026-84218
8.1 HIGH

A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to …

Sep 1, 2026
CVE-2026-79684
8.8 HIGH

Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain …

Sep 1, 2026
CVE-2026-58572
8.8 HIGH

Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges.

Sep 1, 2026
CVE-2026-58571
8.8 HIGH

Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root …

Sep 1, 2026
CVE-2026-51766
7.5 HIGH

Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out …

Sep 1, 2026
CVE-2026-19513
8.1 HIGH

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient …

Sep 1, 2026
CVE-2024-14047
7.2 HIGH

A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with …

Sep 1, 2026
CVE-2026-84145
7.5 HIGH

Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another …

Sep 1, 2026
CVE-2026-84131
8.8 HIGH

Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR …

Sep 1, 2026
CVE-2026-84128
8.8 HIGH

Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

Sep 1, 2026
CVE-2026-84123
8.8 HIGH

Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Sep 1, 2026
CVE-2026-84117
8.8 HIGH

Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.

Sep 1, 2026
CVE-2026-79683
8.8 HIGH

Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write attacker-controlled content to arbitrary …

Sep 1, 2026
CVE-2026-58575
8.8 HIGH

Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges to Administrator.

Sep 1, 2026
CVE-2026-84199
7.7 HIGH

Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, …

Sep 1, 2026
CVE-2026-84196
7.7 HIGH

Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecting user-controlled input through …

Sep 1, 2026
CVE-2026-84195
7.7 HIGH

Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate …

Sep 1, 2026
CVE-2026-84192
7.1 HIGH

LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without escaping. An attacker who controls …

Sep 1, 2026
CVE-2026-84190
7.2 HIGH

LibreNMS versions before 26.5.0 contain a remote code execution vulnerability in the AboutController where the snmpget configuration parameter is passed to shell_exec() without proper validation. …

Sep 1, 2026
CVE-2026-84189
8.1 HIGH

LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the device showconfig page …

Sep 1, 2026
CVE-2026-84187
8.2 HIGH

AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows unauthenticated attackers to mark arbitrary scheduled broadcasts as failed by sending crafted POST requests with …

Sep 1, 2026
CVE-2026-83595
8.1 HIGH

AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform state-changing actions by crafting GET requests that bypass CSRF protection. Attackers …

Sep 1, 2026
CVE-2026-76111
8.8 HIGH

Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege …

Sep 1, 2026
CVE-2026-84059
7.4 HIGH

A flaw has been found in ICP DAS UA-2200 and UA-5200 up to 20260704. The affected element is the function ArmAngstromInstructionSet of the file /CGI?RestApi=SetHostname. …

Sep 1, 2026
CVE-2026-59681
8.8 HIGH

A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory configuration values to execute arbitrary commands as root on the configured …

Sep 1, 2026
CVE-2026-59680
8.0 HIGH

An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of a user, get_password_term() in src/include/users/dialogs.rb read the shadowLastChange and …

Sep 1, 2026
CVE-2026-25706
7.5 HIGH

Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree …

Sep 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.