CVE Database

130945+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-63127
8.2 HIGH

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 …

Sep 16, 2026
CVE-2026-61709
5.3 MEDIUM

OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded …

Sep 16, 2026
CVE-2026-19668
5.3 MEDIUM

A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on …

Sep 16, 2026
CVE-2026-19666
7.5 HIGH

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process …

Sep 16, 2026
CVE-2026-19033
6.5 MEDIUM

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message …

Sep 16, 2026
CVE-2026-18212
7.5 HIGH

A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom …

Sep 16, 2026
CVE-2025-36591
4.4 MEDIUM

Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability. A …

Sep 16, 2026
CVE-2026-92469
8.1 HIGH

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate …

Sep 16, 2026
CVE-2026-92468
6.5 MEDIUM

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the …

Sep 16, 2026
CVE-2026-92467
8.3 HIGH

zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by …

Sep 16, 2026
CVE-2026-92466
8.8 HIGH

zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated users with …

Sep 16, 2026
CVE-2026-92365
4.3 MEDIUM

A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py. The manipulation results …

Sep 16, 2026
CVE-2026-92364
6.3 MEDIUM

A vulnerability has been found in itsourcecode Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /module/employee/index.php. The manipulation …

Sep 16, 2026
CVE-2026-92363
4.3 MEDIUM

A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_parser.cpp of the component JSON Parser. Executing a …

Sep 16, 2026
CVE-2026-92362
7.3 HIGH

A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the file crates/ag-ui-client/src/sse.rs of the component SSE Frame Parser. Performing a …

Sep 16, 2026
CVE-2026-92141
4.3 MEDIUM

Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

Sep 16, 2026
CVE-2026-92140
6.8 MEDIUM

Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in build causes, resulting in a stored cross-site …

Sep 16, 2026
CVE-2026-92139
6.5 MEDIUM

Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials …

Sep 16, 2026
CVE-2026-92138
4.2 MEDIUM

The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the submitted form rather than from the …

Sep 16, 2026
CVE-2026-92137
8.8 HIGH

Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the build …

Sep 16, 2026
CVE-2026-92136
8.0 HIGH

Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the Jenkins UI, resulting in a stored cross-site scripting …

Sep 16, 2026
CVE-2026-92135
8.0 HIGH

Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configuration is submitted through the REST API, allowing attackers …

Sep 16, 2026
CVE-2026-92134
8.0 HIGH

Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results ID when a job configuration is submitted through the REST API, allowing attackers …

Sep 16, 2026
CVE-2026-92133
5.4 MEDIUM

Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the …

Sep 16, 2026
CVE-2026-92132
5.4 MEDIUM

Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity server …

Sep 16, 2026
CVE-2026-92131
4.2 MEDIUM

Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside …

Sep 16, 2026
CVE-2026-92130
3.1 LOW

Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure …

Sep 16, 2026
CVE-2026-92129
7.5 HIGH

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime, allowing attackers …

Sep 16, 2026
CVE-2026-92128
7.5 HIGH

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and loading the …

Sep 16, 2026
CVE-2026-92127
8.0 HIGH

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall/Administer permission copies the item, …

Sep 16, 2026
CVE-2026-92126

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, allowing attackers with permission to define …

Sep 16, 2026
CVE-2026-92125
8.8 HIGH

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, …

Sep 16, 2026
CVE-2026-92124
8.8 HIGH

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a sandboxed script …

Sep 16, 2026
CVE-2026-92123
8.8 HIGH

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribute accesses, and array accesses), …

Sep 16, 2026
CVE-2026-92122
8.8 HIGH

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a value to …

Sep 16, 2026
CVE-2026-91843
9.8 CRITICAL

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

Sep 16, 2026
CVE-2026-89030
4.3 MEDIUM

Adenion Blog2Social plugin for WordPress before 9.1.0 exposes the email addresses of all registered WordPress users to low-privileged accounts. The b2s_search_user AJAX handler in includes/Ajax/Get.php …

Sep 16, 2026
CVE-2026-89029
4.3 MEDIUM

Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to enumerate WordPress user accounts. The b2s_get_select_mandant_user AJAX handler in includes/Ajax/Get.php resolves arbitrary user IDs …

Sep 16, 2026
CVE-2026-89028
7.5 HIGH

MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by …

Sep 16, 2026
CVE-2026-85104

In Sooma 2GEN brain stimulator, an attacker within Bluetooth range can make unauthenticated changes to brain stimulation parameters.

Sep 16, 2026
CVE-2026-81736
7.5 HIGH

If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will …

Sep 16, 2026
CVE-2026-81563
7.5 HIGH

A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens …

Sep 16, 2026
CVE-2026-78301
5.8 MEDIUM

A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a …

Sep 16, 2026
CVE-2026-77692
7.5 HIGH

An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection …

Sep 16, 2026
CVE-2026-73177

Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware upgrade mechanism of the Advantech EKI-1242EIMS in firmware version V1.06.01. …

Sep 16, 2026
CVE-2026-61598

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.mixins.model_binding.ModelBindingMixin` provides a default `update_model` event handler and is …

Sep 16, 2026
CVE-2026-61590
7.4 HIGH

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's observability endpoints expose live view/session state and a …

Sep 16, 2026
CVE-2026-56719
6.5 MEDIUM

MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the …

Sep 16, 2026
CVE-2026-19941
5.9 MEDIUM

An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same …

Sep 16, 2026
CVE-2026-19667
7.5 HIGH

If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache …

Sep 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.