CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-76839
6.5 MEDIUM

Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and offsetexists() methods that lack field filtering. Attackers with page-edit …

Aug 25, 2026
CVE-2026-75575
5.3 MEDIUM

Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauthenticated caller may invoke it as often as it likes. The method …

Aug 25, 2026
CVE-2026-72702
5.4 MEDIUM

Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, which validate the Referer header using an unanchored string prefix …

Aug 25, 2026
CVE-2026-72699
5.3 MEDIUM

The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register() method in classes/Login.php throws a distinct exception (EMAIL_NOT_AVAILABLE) when a …

Aug 25, 2026
CVE-2026-72698
6.5 MEDIUM

Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing content editors to read sensitive configuration values. …

Aug 25, 2026
CVE-2026-72697
6.5 MEDIUM

Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function that fails to validate filesystem paths, allowing authenticated users to enumerate …

Aug 25, 2026
CVE-2026-56708
5.3 MEDIUM

Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delivery that allows attackers to bypass hostname validation by DNS rebinding. Attackers …

Aug 25, 2026
CVE-2026-56706
6.8 MEDIUM

Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value in every token (format (rand XOR secret):rand), …

Aug 25, 2026
CVE-2026-56704
6.1 MEDIUM

Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server …

Aug 25, 2026
CVE-2026-34967
5.4 MEDIUM

Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php. An authenticated user …

Aug 25, 2026
CVE-2026-34964
5.8 MEDIUM

Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, which only inspects leading integers for privileged ports and …

Aug 25, 2026
CVE-2026-34959
4.7 MEDIUM

Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no trusted-proxy check and no validation of the prefix value. An attacker can …

Aug 25, 2026
CVE-2026-19801
4.3 MEDIUM

The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnerable to authorization bypass in all versions up …

Aug 25, 2026
CVE-2026-15023
6.5 MEDIUM

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to generic SQL Injection via Stored 'meta_key' via Event/Location Duplicate Action …

Aug 25, 2026
CVE-2026-10630
4.3 MEDIUM

The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in …

Aug 25, 2026
CVE-2026-59183
5.5 MEDIUM

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.1.0 through 3.2.10, 3.3.0 …

Aug 25, 2026
CVE-2026-55373
6.2 MEDIUM

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12, and …

Aug 25, 2026
CVE-2026-55059
6.1 MEDIUM

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12 and …

Aug 25, 2026
CVE-2026-78434
6.5 MEDIUM

A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. …

Aug 24, 2026
CVE-2026-78266
6.5 MEDIUM

Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.

Aug 24, 2026
CVE-2026-68516
6.5 MEDIUM

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a …

Aug 24, 2026
CVE-2026-27364
6.5 MEDIUM

Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.

Aug 24, 2026
CVE-2026-17113
6.0 MEDIUM

A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in `server/container_create.go`). When a `CreateContainer` request supplies a `nil` CRI …

Aug 24, 2026
CVE-2026-5006
6.8 MEDIUM

A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated …

Aug 24, 2026
CVE-2026-56136
4.7 MEDIUM

In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process …

Aug 24, 2026
CVE-2026-55468
4.3 MEDIUM

Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the …

Aug 24, 2026
CVE-2026-16782
5.3 MEDIUM

A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to …

Aug 24, 2026
CVE-2026-16781
5.5 MEDIUM

A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to …

Aug 24, 2026
CVE-2022-30983
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows remote attackers to inject arbitrary web script or HTML via the …

Aug 24, 2026
CVE-2026-78430
5.3 MEDIUM

A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall of the file src/tools/handlers.ts of the component Tool Handler. The manipulation of …

Aug 24, 2026
CVE-2026-77923
4.3 MEDIUM

Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in the private-project membership check within the clonetasks mass action …

Aug 24, 2026
CVE-2026-77310
5.3 MEDIUM

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release …

Aug 24, 2026
CVE-2026-75509
6.5 MEDIUM

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership …

Aug 24, 2026
CVE-2026-72714
6.3 MEDIUM

Rocq Prover does not restore the universe graph's copy of the universe checking flag when a module that locally disabled the check is closed. Local …

Aug 24, 2026
CVE-2026-72711
6.3 MEDIUM

The Lean 4 kernel does not check that the body of an opaque declaration is closed. environment::add_opaque omits the check_no_metavar_no_fvar call that the definition and …

Aug 24, 2026
CVE-2026-72705
6.3 MEDIUM

The guard checker in Rocq Prover does not follow recursive calls made through a fixpoint's own arguments. A fixpoint may pass itself as a higher-order …

Aug 24, 2026
CVE-2026-72704
6.3 MEDIUM

The guard checker in Rocq Prover does not recheck the recursive tree representation of an inductive type parameter after that parameter has been changed by …

Aug 24, 2026
CVE-2026-72703
6.3 MEDIUM

The guard checker in Rocq Prover treats a parameter of a nested mutual fixpoint as uniform without examining calls between the different bodies of that …

Aug 24, 2026
CVE-2026-71511
6.5 MEDIUM

Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticated attackers with member-read rights to retrieve bcrypt password …

Aug 24, 2026
CVE-2026-71510
6.5 MEDIUM

Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by …

Aug 24, 2026
CVE-2026-63693
6.6 MEDIUM

Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this …

Aug 24, 2026
CVE-2020-37268
6.3 MEDIUM

Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition reaches the caller through Parameter Inline in …

Aug 24, 2026
CVE-2026-78417
4.3 MEDIUM

Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to …

Aug 24, 2026
CVE-2026-75370
6.5 MEDIUM

An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via …

Aug 24, 2026
CVE-2026-71832
6.2 MEDIUM

Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial …

Aug 24, 2026
CVE-2026-71509
6.5 MEDIUM

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint that allows authenticated attackers with expense-creation rights to bypass …

Aug 24, 2026
CVE-2026-71508
6.5 MEDIUM

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields …

Aug 24, 2026
CVE-2026-71507
6.5 MEDIUM

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation …

Aug 24, 2026
CVE-2026-71503
6.1 MEDIUM

Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding …

Aug 24, 2026
CVE-2026-78475
6.1 MEDIUM

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array …

Aug 24, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.