CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-77763
6.5 MEDIUM

The filestore backend in pkg/object/file.go, used for file:// stores and as a common juicefs sync destination, derived every operation's target from path(key), which returned either …

Aug 21, 2026
CVE-2026-77686
5.4 MEDIUM

A weakness has been identified in Dolibarr up to 23.0.4. This affects an unknown part of the file htdocs/user/card.php of the component Account Handler. This …

Aug 21, 2026
CVE-2026-59296
5.9 MEDIUM

Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous antipattern that general-purpose instrumentation should …

Aug 21, 2026
CVE-2026-77681
6.3 MEDIUM

A vulnerability was identified in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/update-profile.php. The manipulation of …

Aug 21, 2026
CVE-2026-59323
5.3 MEDIUM

An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded object allocation …

Aug 21, 2026
CVE-2026-74866
5.8 MEDIUM

@fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits header lines only on the two-byte carriage-return line-feed sequence, so a lone …

Aug 21, 2026
CVE-2026-66797
5.4 MEDIUM

Improper access control in CloudStack's annotation functionality allows unauthorized comment creation and disclosure. The addAnnotation and listAnnotation APIs perform an ownership check when an entity's …

Aug 21, 2026
CVE-2026-65613
4.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webhook module while listing and deleting deliveries. This issue affects Apache CloudStack: from …

Aug 21, 2026
CVE-2026-61422
4.3 MEDIUM

Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration functionality. When registering a template or ISO, CloudStack makes a live HTTP HEAD/GET call …

Aug 21, 2026
CVE-2026-61399
4.8 MEDIUM

Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock User Functionality. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 …

Aug 21, 2026
CVE-2026-73537
4.7 MEDIUM

Cross-site scripting vulnerability exists in Miraikan Assist App. If this vulnerability is exploited, an arbitrary script may be executed in the browser component (WebView) running …

Aug 21, 2026
CVE-2026-19441
5.3 MEDIUM

Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data. This issue affects Rush: through 21082026. NOTE: The …

Aug 21, 2026
CVE-2026-16962
5.3 MEDIUM

The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its public payment cancel/fail return URLs, …

Aug 21, 2026
CVE-2026-16959
6.8 MEDIUM

The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its …

Aug 21, 2026
CVE-2026-16575
5.3 MEDIUM

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict access to per-vendor commission configuration returned by one of its …

Aug 21, 2026
CVE-2026-14601
6.8 MEDIUM

The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated …

Aug 21, 2026
CVE-2026-13736
5.3 MEDIUM

The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read …

Aug 21, 2026
CVE-2025-15671
5.4 MEDIUM

The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier from a user-supplied request parameter, …

Aug 21, 2026
CVE-2026-65645
4.3 MEDIUM

Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid …

Aug 21, 2026
CVE-2026-45202
5.5 MEDIUM

Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU memory leaks and possible kernel heap corruption. Scenario caused …

Aug 21, 2026
CVE-2026-76131
5.3 MEDIUM

Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an attacker to impersonate a legitimate VOCALOID6 Editor and gain access to Yamaha's …

Aug 21, 2026
CVE-2026-77392
6.3 MEDIUM

A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file …

Aug 21, 2026
CVE-2026-77391
4.3 MEDIUM

A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation …

Aug 21, 2026
CVE-2026-20679
4.3 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. Processing a maliciously crafted …

Aug 21, 2026
CVE-2026-77643
4.4 MEDIUM

A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue …

Aug 20, 2026
CVE-2026-72846
6.4 MEDIUM

Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/clients/MicrosoftTeams/MicrosoftTeamsClient.ts. In affected versions …

Aug 20, 2026
CVE-2026-70105
6.5 MEDIUM

Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Aug 20, 2026
CVE-2026-67448
6.5 MEDIUM

Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw RequestURI for the /api/ …

Aug 20, 2026
CVE-2026-67447
5.3 MEDIUM

Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's internal/smtpd/smtpd.go readData() function calls bufio.Reader.ReadBytes before applying the len(data)+len(line) size …

Aug 20, 2026
CVE-2026-62945
4.3 MEDIUM

TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions accept attacker-controlled reservation_id, place_id, and assignment_id values without using …

Aug 20, 2026
CVE-2026-55491
5.4 MEDIUM

BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape meetingName in record-and-playback/screenshare/playback/index.html.erb when generating the screenshare playback format. A low-privileged user …

Aug 20, 2026
CVE-2026-55489
4.9 MEDIUM

BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could submit a presentationId through /api/graphql that identified a presentation belonging to another meeting. …

Aug 20, 2026
CVE-2026-55015
5.5 MEDIUM

Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.

Aug 20, 2026
CVE-2026-54509
6.5 MEDIUM

TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link route in server/src/routes/journey.ts returns the result of getJourneyShareLink() from server/src/services/journeyShareService.ts without checking …

Aug 20, 2026
CVE-2026-54389
5.5 MEDIUM

Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser that allows attackers to terminate the Ghidra process by supplying a crafted …

Aug 20, 2026
CVE-2026-49244
5.9 MEDIUM

SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP download endpoint for a browsable share validates …

Aug 20, 2026
CVE-2026-19783
6.7 MEDIUM

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation. A …

Aug 20, 2026
CVE-2026-19448
6.5 MEDIUM

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation …

Aug 20, 2026
CVE-2026-18828
5.4 MEDIUM

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a stack-based …

Aug 20, 2026
CVE-2026-18822
4.4 MEDIUM

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to uncontrolled resource …

Aug 20, 2026
CVE-2026-17424
4.8 MEDIUM

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restrictions due to improper limitation of a …

Aug 20, 2026
CVE-2026-17195
6.5 MEDIUM

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to an out-of-bounds …

Aug 20, 2026
CVE-2026-17120
5.3 MEDIUM

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a buffer …

Aug 20, 2026
CVE-2026-17009
4.7 MEDIUM

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to a NULL …

Aug 20, 2026
CVE-2026-17007
6.7 MEDIUM

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information or cause a denial of service …

Aug 20, 2026
CVE-2026-16980
6.3 MEDIUM

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to improper validation …

Aug 20, 2026
CVE-2026-16973
5.5 MEDIUM

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to disclose sensitive kernel memory due to an out-of-bounds read.

Aug 20, 2026
CVE-2026-16972
6.5 MEDIUM

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to improper authentication.

Aug 20, 2026
CVE-2026-16964
6.5 MEDIUM

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages and forge replies due to the exposure …

Aug 20, 2026
CVE-2026-16958
6.5 MEDIUM

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds …

Aug 20, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.