CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-16952
5.5 MEDIUM

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to uncontrolled resource …

Aug 20, 2026
CVE-2026-16951
6.7 MEDIUM

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local authenticated attacker to execute arbitrary code due to a heap-based buffer …

Aug 20, 2026
CVE-2026-16944
6.7 MEDIUM

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a stack-based buffer overflow.

Aug 20, 2026
CVE-2026-77641
6.5 MEDIUM

tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() was ignored, so …

Aug 20, 2026
CVE-2026-77639
5.3 MEDIUM

Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream …

Aug 20, 2026
CVE-2026-77587
5.9 MEDIUM

Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose …

Aug 20, 2026
CVE-2026-77506
4.8 MEDIUM

Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.

Aug 20, 2026
CVE-2026-68921
4.7 MEDIUM

DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpolates the rotate option into an SVG transform attribute without XML escaping …

Aug 20, 2026
CVE-2026-67446
5.3 MEDIUM

Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-supplied image attachments into a full raster before checking decoded …

Aug 20, 2026
CVE-2026-67445
5.3 MEDIUM

Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit reads SMTP commands through internal/smtpd/smtpd.go session.readLine() using bufio.Reader.ReadString before session.parseLine() parses …

Aug 20, 2026
CVE-2026-75910
6.5 MEDIUM

Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an authenticated remote user to read …

Aug 20, 2026
CVE-2026-72861
5.8 MEDIUM

The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition. verifyWebhook in node/github-issue-bot/src/github.js and in node-typescript/github-issue-bot/src/github.ts returns "typeof signature !== 'string' …

Aug 20, 2026
CVE-2026-75526
4.4 MEDIUM

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. From 5.0.8 until 5.0.9, ContentRenderer.render_placeholder in cms/plugin_rendering.py can pass stored, attacker-controlled …

Aug 20, 2026
CVE-2026-75514
5.9 MEDIUM

BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklist, greylist, and antibot modules in src/common/core/blacklist/blacklist.lua, src/common/core/greylist/greylist.lua, and src/common/core/antibot/antibot.lua trust PTR suffix …

Aug 20, 2026
CVE-2026-72854
5.3 MEDIUM

msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_buffer API, computes its new buffer size using an unchecked size_t addition of the requested size and the …

Aug 20, 2026
CVE-2026-64777
4.3 MEDIUM

A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name …

Aug 20, 2026
CVE-2026-63003
6.5 MEDIUM

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, page duplication lacks an object-level authorization check on …

Aug 20, 2026
CVE-2026-61663
4.3 MEDIUM

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, render_object_structure fails to authorize non-PageContent objects that use …

Aug 20, 2026
CVE-2026-54624
6.5 MEDIUM

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, render_object_structure in cms/views.py renders cms/toolbar/structure.html for a PageContent …

Aug 20, 2026
CVE-2026-54622
6.5 MEDIUM

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the copy_plugins endpoint in cms/admin/placeholderadmin.py authorizes only the …

Aug 20, 2026
CVE-2026-53586
6.5 MEDIUM

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality …

Aug 20, 2026
CVE-2026-53585
5.3 MEDIUM

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality …

Aug 20, 2026
CVE-2026-53584
4.3 MEDIUM

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality …

Aug 20, 2026
CVE-2026-53583
6.5 MEDIUM

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality …

Aug 20, 2026
CVE-2026-43678
5.3 MEDIUM

An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping …

Aug 20, 2026
CVE-2026-77036
6.3 MEDIUM

A vulnerability was found in elunez eladmin up to 2.7. The impacted element is the function EmailController/AliPayController/GeneratorController/GenConfigController. The manipulation results in improper authorization. The attack …

Aug 20, 2026
CVE-2026-73259
5.4 MEDIUM

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment …

Aug 20, 2026
CVE-2026-73258
6.5 MEDIUM

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in …

Aug 20, 2026
CVE-2026-73255
6.5 MEDIUM

Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control an SSI-enabled file can place directory traversal sequences …

Aug 20, 2026
CVE-2026-73254
5.4 MEDIUM

Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its …

Aug 20, 2026
CVE-2026-72847
4.6 MEDIUM

broot renders each file and directory name in its interactive tree view exactly as read from the filesystem. Names are converted with a plain to_string_lossy() …

Aug 20, 2026
CVE-2026-72844
6.3 MEDIUM

The Lean 4 kernel does not verify that the structure named in a projection expression matches the type of the value being projected, and environment::add_inductive …

Aug 20, 2026
CVE-2026-54625
4.8 MEDIUM

django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request …

Aug 20, 2026
CVE-2026-77025
6.3 MEDIUM

A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentpending.php. This manipulation of the argument …

Aug 20, 2026
CVE-2026-61625
6.8 MEDIUM

VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.25, 1.136.12, and 1.146.0, vmrestore does not validate backup part path …

Aug 20, 2026
CVE-2026-55586
6.6 MEDIUM

SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, a crafted CHM file can supply malformed LZX Huffman code lengths to make_decode_table in …

Aug 20, 2026
CVE-2026-54770
6.1 MEDIUM

WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double …

Aug 20, 2026
CVE-2026-18273
6.6 MEDIUM

Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows physically present attackers to escalate privileges on affected installations of Kenwood DNR1007XR …

Aug 20, 2026
CVE-2026-18272
6.8 MEDIUM

Kenwood DNR1007XR startUpdateProcess Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is …

Aug 20, 2026
CVE-2026-18271
6.8 MEDIUM

Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR …

Aug 20, 2026
CVE-2026-18269
6.8 MEDIUM

Kenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. …

Aug 20, 2026
CVE-2026-18267
6.8 MEDIUM

Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR …

Aug 20, 2026
CVE-2026-76999
6.3 MEDIUM

A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing …

Aug 20, 2026
CVE-2026-76997
6.3 MEDIUM

A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=save_category. This …

Aug 20, 2026
CVE-2026-63044
5.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Apache InLong. Any authenticated user (no admin role required) can cause the InLong Manager server to make outbound HTTP …

Aug 20, 2026
CVE-2026-63016
5.3 MEDIUM

Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration or allow upload of non-official packages. This issue affects Apache InLong: from 2.0.0 …

Aug 20, 2026
CVE-2026-63015
4.3 MEDIUM

Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons can view template information. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are …

Aug 20, 2026
CVE-2026-76995
4.7 MEDIUM

A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_menu. The manipulation of …

Aug 20, 2026
CVE-2026-76993
5.0 MEDIUM

A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown code of the component Web-Page Crawling. Executing a manipulation of the …

Aug 20, 2026
CVE-2026-76991
6.3 MEDIUM

A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentapproved.php. Performing a manipulation of the argument …

Aug 20, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.