CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-39113
4.0 MEDIUM

Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror 169f68ed88b34cb68f720191c64c058f2ccec508, 2026-03-11) and later snapshots/builds allows an attacker to cause …

Aug 25, 2026
CVE-2026-77585
5.3 MEDIUM

The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may …

Aug 25, 2026
CVE-2026-68514
5.5 MEDIUM

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 …

Aug 25, 2026
CVE-2026-65367
5.5 MEDIUM

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5. …

Aug 25, 2026
CVE-2026-64705
5.5 MEDIUM

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7. An app may be able …

Aug 25, 2026
CVE-2026-80050
6.5 MEDIUM

ContiNew Admin fails to apply file-upload permission checks or file-type allowlist validation to multipart upload endpoints, allowing authenticated users to store files with arbitrary extensions. …

Aug 25, 2026
CVE-2026-62986
4.3 MEDIUM

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 …

Aug 25, 2026
CVE-2026-61555
5.5 MEDIUM

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through …

Aug 25, 2026
CVE-2026-59985
5.5 MEDIUM

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.2.0 through 3.2.10, 3.3.0 …

Aug 25, 2026
CVE-2026-55663
5.6 MEDIUM

mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, …

Aug 25, 2026
CVE-2026-55619
5.3 MEDIUM

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to …

Aug 25, 2026
CVE-2026-55618
6.5 MEDIUM

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to …

Aug 25, 2026
CVE-2026-76198
5.5 MEDIUM

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability …

Aug 25, 2026
CVE-2026-76189
6.2 MEDIUM

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this …

Aug 25, 2026
CVE-2026-75752
5.5 MEDIUM

Substance3D - Painter is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to …

Aug 25, 2026
CVE-2026-71444
6.2 MEDIUM

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this …

Aug 25, 2026
CVE-2026-71441
5.5 MEDIUM

Illustrator is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive …

Aug 25, 2026
CVE-2026-59984
5.5 MEDIUM

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.1.0 through 3.2.10, 3.3.0 …

Aug 25, 2026
CVE-2026-59983
5.5 MEDIUM

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through …

Aug 25, 2026
CVE-2026-55419
5.3 MEDIUM

Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8.2, the Reachy Mini daemon exposes the /api/media/sounds/upload endpoint implemented by the upload_sound …

Aug 25, 2026
CVE-2026-48429
5.5 MEDIUM

Substance3D - Designer is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to …

Aug 25, 2026
CVE-2026-26211
4.8 MEDIUM

Ekushey Project Manager CRM stores the administrator-configured system name and writes it to the login page without output encoding. The value is emitted in three …

Aug 25, 2026
CVE-2026-78468
6.5 MEDIUM

The FluentCRM Pro – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin for WordPress is vulnerable to SQL Injection in …

Aug 25, 2026
CVE-2026-47624
6.0 MEDIUM

NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of this vulnerability …

Aug 25, 2026
CVE-2026-24225
6.0 MEDIUM

NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read. A successful exploit …

Aug 25, 2026
CVE-2026-24168
6.8 MEDIUM

NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker with administrative privileges may cause command injection by sending crafted API …

Aug 25, 2026
CVE-2026-24167
6.8 MEDIUM

NVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authenticated administrator could inject commands by sending a crafted API request. A …

Aug 25, 2026
CVE-2026-24166
5.1 MEDIUM

NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-coded cryptographic key to extract information. A successful …

Aug 25, 2026
CVE-2026-18445
6.6 MEDIUM

There is an integer overflow vulnerability resulting in an out-of-bounds write recently discovered in NI LabVIEW. This may result in information disclosure or arbitrary code …

Aug 25, 2026
CVE-2026-18444
6.6 MEDIUM

There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered in NI LabVIEW. This may result in information disclosure …

Aug 25, 2026
CVE-2026-13478
5.5 MEDIUM

The Zephyr ext2 filesystem driver validates the on-disk block bitmap in ext2_init_fs() (subsys/fs/ext2/ext2_impl.c) by passing fs_blocks = s_blocks_count - s_first_data_block to ext2_bitmap_count_set(). That helper (subsys/fs/ext2/ext2_bitmap.c) …

Aug 25, 2026
CVE-2026-13217
5.9 MEDIUM

The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the uid field of a CALLRESULT message. In ocpp_process_server_msg() the code …

Aug 25, 2026
CVE-2026-13216
6.1 MEDIUM

The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's PCI capability list during driver initialization. In virtio_pci_read_cap() the device-supplied capability length byte cap_len (read from PCI …

Aug 25, 2026
CVE-2026-79785
5.9 MEDIUM

X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in anylabeling/services/auto_labeling/model.py built a context with ssl._create_unverified_context() and passed it to urllib.request.urlopen, so neither the certificate chain …

Aug 25, 2026
CVE-2026-79781
6.5 MEDIUM

rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 …

Aug 25, 2026
CVE-2026-79780
5.3 MEDIUM

rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme …

Aug 25, 2026
CVE-2026-79779
5.3 MEDIUM

rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after …

Aug 25, 2026
CVE-2026-79778
5.3 MEDIUM

rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a nil response before checking for transport errors. …

Aug 25, 2026
CVE-2026-79776
5.3 MEDIUM

rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler. Attackers can access …

Aug 25, 2026
CVE-2026-79775
6.5 MEDIUM

rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vulnerabilities in the archive backend's SquashFS parser, which relies on the github.com/diskfs/go-diskfs …

Aug 25, 2026
CVE-2026-79773
4.9 MEDIUM

Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter that allows authenticated users with cms.manage_assets permission to disclose arbitrary server-readable …

Aug 25, 2026
CVE-2026-79772
5.3 MEDIUM

Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on failure instead of raising …

Aug 25, 2026
CVE-2026-79771
5.3 MEDIUM

Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strings containing null bytes. Attackers can exploit this …

Aug 25, 2026
CVE-2026-79769
5.5 MEDIUM

Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protected internal Node#initialize_copy_with_args helper behind Node#dup and #clone, which unwrapped its source …

Aug 25, 2026
CVE-2026-79676
5.9 MEDIUM

NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths using built-in open() instead of nltk.pathsec.open(), allowing symlinks to …

Aug 25, 2026
CVE-2026-70550
6.5 MEDIUM

An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are …

Aug 25, 2026
CVE-2024-58377
5.5 MEDIUM

Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xmllint tool. Nokogiri 1.16.5 upgrades the bundled libxml2 to 2.12.7 to …

Aug 25, 2026
CVE-2026-79717
6.4 MEDIUM

A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server plugin for Pulp. An authenticated user with namespace management permissions can …

Aug 25, 2026
CVE-2026-55535
6.8 MEDIUM

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_url() path fails open on socket.gaierror and does not bind the validated …

Aug 25, 2026
CVE-2026-55531
6.5 MEDIUM

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream mcp_post handler creates a new _sessions entry for every initialize request …

Aug 25, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.