CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-76837
6.4 MEDIUM

Baserow interpolates a user's display name into the rich-text mention markup without HTML encoding. PATCH /api/user/account/ stores the first_name value verbatim, and the mention renderer …

Aug 24, 2026
CVE-2026-71932
4.9 MEDIUM

Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A …

Aug 24, 2026
CVE-2026-71920
4.9 MEDIUM

Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or …

Aug 24, 2026
CVE-2026-13213
5.3 MEDIUM

The Hearing Access Service (HAS) GATT server in subsys/bluetooth/audio/has.c installs a connection-callback set unconditionally via BT_CONN_CB_DEFINE, so security_changed() runs for every connection that establishes security …

Aug 24, 2026
CVE-2026-77914
6.5 MEDIUM

rConfig Core 8.0.0 before 8.2.13 contains a path traversal vulnerability that allows authenticated users to read arbitrary files by supplying crafted filenames containing directory traversal …

Aug 24, 2026
CVE-2026-75099
5.3 MEDIUM

Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through 1.19.1. Users are recommended to upgrade to version 1.20.0, …

Aug 24, 2026
CVE-2026-63621
5.3 MEDIUM

Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Knative component The Knative consumer …

Aug 24, 2026
CVE-2026-60093
5.5 MEDIUM

Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 …

Aug 24, 2026
CVE-2026-59230
6.5 MEDIUM

Improper input validation vulnerability in Apache Camel. This issue affects Apache Camel: from 2.17.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The …

Aug 24, 2026
CVE-2026-67204
5.4 MEDIUM

BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by …

Aug 24, 2026
CVE-2026-13343
5.3 MEDIUM

The UMP Stream responder library in lib/midi2/ump_stream_responder.c builds reply packets in a 16-byte struct midi_ump (uint32_t data[4]). The builders make_endpoint_info() and make_function_block_info() populate only the …

Aug 24, 2026
CVE-2026-9728
6.4 MEDIUM

The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out of live userspace memory, and then forwarded the …

Aug 24, 2026
CVE-2026-65053
6.1 MEDIUM

Horde IMP's AppleDouble MIME viewer writes an attacker-controlled attachment name into an HTML status block without escaping it. In lib/Mime/Viewer/Appledouble.php, _IMPrender() obtains the name of …

Aug 24, 2026
CVE-2026-39914
6.5 MEDIUM

TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arbitrary SQL queries to a privileged dashboard Excel export …

Aug 24, 2026
CVE-2026-21755
5.3 MEDIUM

HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or credential stuffing attacks, or cause a …

Aug 24, 2026
CVE-2026-78250
4.3 MEDIUM

A vulnerability was identified in bytebot-ai bytebot 0.0.1. The affected element is an unknown function of the component Agent Execution Workflow. Such manipulation leads to …

Aug 24, 2026
CVE-2026-76845
6.5 MEDIUM

adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. Utils.sanitize in util/utils.js enforces containment by comparing only the string form of an archive …

Aug 24, 2026
CVE-2026-17033
6.8 MEDIUM

An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert containing a controlled generatorURL. The attacker is authorized to create the …

Aug 24, 2026
CVE-2025-68833
5.3 MEDIUM

HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources.

Aug 24, 2026
CVE-2026-21759
4.3 MEDIUM

HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly. Although no sensitive information (e.g., credentials, PII) was discovered, …

Aug 24, 2026
CVE-2026-78323
6.5 MEDIUM

A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present …

Aug 24, 2026
CVE-2026-78291
5.3 MEDIUM

Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.

Aug 24, 2026
CVE-2026-78290
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.

Aug 24, 2026
CVE-2026-78280
4.3 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.

Aug 24, 2026
CVE-2026-78279
5.4 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions.

Aug 24, 2026
CVE-2026-78278
5.3 MEDIUM

Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.

Aug 24, 2026
CVE-2026-78277
4.9 MEDIUM

Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.

Aug 24, 2026
CVE-2026-78272
5.4 MEDIUM

Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions.

Aug 24, 2026
CVE-2026-78269
6.4 MEDIUM

Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions.

Aug 24, 2026
CVE-2026-78258
5.3 MEDIUM

Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.

Aug 24, 2026
CVE-2026-59295
5.9 MEDIUM

It is possible for outbound HTTP requests using a Micrometer-instrumented client to cause a denial-of-service (DoS) condition due to an unbounded memory leak. Micrometer 1.17.0 …

Aug 24, 2026
CVE-2026-10618
5.4 MEDIUM

Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them. New in markup/internal/attributes/attributes.go converts every …

Aug 24, 2026
CVE-2026-8173
5.3 MEDIUM

The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned …

Aug 24, 2026
CVE-2026-78200
6.3 MEDIUM

A flaw has been found in itsourcecode Library Management System 1.0. The affected element is an unknown function of the file editbooks.php. Executing a manipulation …

Aug 24, 2026
CVE-2026-78196
4.4 MEDIUM

A security flaw has been discovered in achorein expo-share-intent up to 8.0.0. This affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component Android …

Aug 24, 2026
CVE-2026-78186
4.3 MEDIUM

A flaw has been found in Open5GS up to 2.8.0. This affects an unknown function of the file src/hss/hss-cx-path.c of the component HSS. This manipulation …

Aug 24, 2026
CVE-2026-78185
6.3 MEDIUM

A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/cust_edit.php. The manipulation of …

Aug 24, 2026
CVE-2026-78179
6.3 MEDIUM

A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function SetValue of the file plugins/utils/object/SetValue.js of the component BehaviorTree Blackboard …

Aug 24, 2026
CVE-2026-19853
5.3 MEDIUM

NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a specific functionality to send emails to anyone on behalf …

Aug 24, 2026
CVE-2026-19852
6.1 MEDIUM

NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload arbitrary files, including malicious HTML files, thereby achieving effects …

Aug 24, 2026
CVE-2026-78177
4.5 MEDIUM

A vulnerability was found in TanStack devtools-vite 0.7.0. Affected by this issue is the function installPackage of the file packages/devtools-bundler-core/src/package-manager.ts of the component Development Devtools …

Aug 24, 2026
CVE-2026-78166
6.3 MEDIUM

A security flaw has been discovered in provectus kafka-ui up to 0.7.2. The affected element is the function executeSmartFilterTest of the file kafka-ui-api/src/main/java/com/provectus/kafka/ui/controller/MessagesController.java of the …

Aug 24, 2026
CVE-2026-78205
5.8 MEDIUM

BentoML's outbound connection safeguard (make_safe_connect in _internal/utils/uri.py) blocks private, loopback, and link-local IP addresses but fails to reject the RFC 6598 shared address space (100.64.0.0/10, …

Aug 24, 2026
CVE-2026-78204
5.4 MEDIUM

Ghostwriter through 7.2.6 does not apply per-object authorization on its report template lint endpoints. RoleBasedAccessControlMixin.test_func returns only request.user.is_active unless a view overrides it, and neither …

Aug 24, 2026
CVE-2026-78160
6.3 MEDIUM

A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. This issue affects some unknown processing of the file /user/note.php of the component User …

Aug 24, 2026
CVE-2026-78158
6.3 MEDIUM

A flaw has been found in Open5GS 2.8.0. This vulnerability affects unknown code of the component AMF UEContextReleaseRequest Path Handler. Executing a manipulation can lead …

Aug 24, 2026
CVE-2026-78148
5.3 MEDIUM

A vulnerability was determined in ggml-org llama.cpp bec4772f6. This affects the function rpc_server::graph_compute of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Executing a manipulation …

Aug 24, 2026
CVE-2026-78145
4.3 MEDIUM

A vulnerability has been found in CTFd up to 3.8.4. The affected element is the function _is_safe_url of the file CTFd/utils/validators/__init__.py. Such manipulation of the …

Aug 23, 2026
CVE-2026-78144
6.3 MEDIUM

A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /boarders.php of …

Aug 23, 2026
CVE-2026-78142
6.3 MEDIUM

A vulnerability was found in code-projects Barangay Resident Profiling Management System 1.0. This impacts an unknown function of the file /archived_records.php of the component Restore/Delete. …

Aug 23, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.