CVE Database

11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-89536
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: wait for in-flight client TLS handshake callback xs_tls_handshake_sync() gives xs_tls_handshake_done() a reference to the …

Sep 11, 2026
CVE-2026-89533
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Fix offset arithmetic in read_chunk_range svc_rdma_read_chunk_range() walks a Read chunk's segment list to build …

Sep 11, 2026
CVE-2026-89532
9.1 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Fix pcl_for_each_segment for empty chunks When a parsed chunk list contains a chunk whose …

Sep 11, 2026
CVE-2026-89530
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject inline replies that overflow the pull-up buffer An RPC-over-RDMA client can request a …

Sep 11, 2026
CVE-2026-89526
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Validate Read chunk positions before reconstruction The RPC/RDMA Read chunk position field is supplied …

Sep 11, 2026
CVE-2026-89495
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ocfs2: bound namelen in dlm_migrate_request_handler Patch series "ocfs2/dlm: bound peer-controlled lengths in the o2dlm". The …

Sep 11, 2026
CVE-2026-89494
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate lengths in dlm_mig_lockres_handler A node receiving a DLM_MIG_LOCKRES message trusts several fields of …

Sep 11, 2026
CVE-2026-89492
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate directory-index entry counts when reading metadata ocfs2_validate_dx_leaf() and ocfs2_validate_dx_root() check the ECC and …

Sep 11, 2026
CVE-2026-89485
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: lockd: pin next file across nlm_inspect_file lock-drop nlm_traverse_files() pins the current file with f_count++ across …

Sep 11, 2026
CVE-2026-89482
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone Commit 25e5cb780e62 ("nvme-tcp: fix possible crash …

Sep 11, 2026
CVE-2026-89479
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: sctp: stop processing a packet once its association is deleted sctp_endpoint_bh_rcv() looks the association up …

Sep 11, 2026
CVE-2026-89478
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: sctp: drop a chunk if its transport was removed sctp_rcv() resolves the transport once per …

Sep 11, 2026
CVE-2026-89448
9.3 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Force requesting ACS when tboot is enabled Currently the conditions of requesting ACS in …

Sep 11, 2026
CVE-2026-81002
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: xdp: fix zero-copy frame layout xdp_convert_zc_to_xdp_frame() clones an XSK packet into an order-0 page and …

Sep 11, 2026
CVE-2026-80986
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages On a link whose device …

Sep 11, 2026
CVE-2026-80981
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() smc_llc_srv_add_link() keeps add_llc pointing into the …

Sep 11, 2026
CVE-2026-80980
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net/smc: stop killed, freed and out_of_sync sharing a byte The three connection state flags are …

Sep 11, 2026
CVE-2026-80976
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: seg6: reset IP6CB after IPv6 decapsulation decap_and_validate() pulls the outer SRv6 headers and makes the …

Sep 11, 2026
CVE-2026-80945
9.1 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - unmap dst before software fallback on decompress On a hardware analytics error, …

Sep 11, 2026
CVE-2026-80926
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in oplock break notification smb2_oplock_break_noti() reads opinfo->conn without any lock and dereferences …

Sep 11, 2026
CVE-2026-53952
9.8 CRITICAL

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS …

Sep 11, 2026
CVE-2026-52630
9.8 CRITICAL

SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEditor.class.php and the update action in UserAction.class.php

Sep 11, 2026
CVE-2026-79396
9.8 CRITICAL

Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled …

Sep 11, 2026
CVE-2026-79395
9.8 CRITICAL

An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows …

Sep 11, 2026
CVE-2026-62105
9.8 CRITICAL

Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.

Sep 11, 2026
CVE-2026-62103
9.8 CRITICAL

Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.

Sep 11, 2026
CVE-2026-54072
9.3 CRITICAL

Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When …

Sep 11, 2026
CVE-2026-82617
9.8 CRITICAL

The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDER.EMAIL and DEFAULT_REGEX_NAME_FINDER.URL - contain ambiguous nested quantifiers. An application that obtains these finders through RegexNameFinderFactory.getDefaultRegexNameFinders(...) …

Sep 11, 2026
CVE-2026-72710
9.8 CRITICAL

SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking …

Sep 11, 2026
CVE-2026-72709
9.8 CRITICAL

SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only …

Sep 11, 2026
CVE-2026-89010
9.8 CRITICAL

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands …

Sep 11, 2026
CVE-2026-89009
9.1 CRITICAL

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file …

Sep 11, 2026
CVE-2026-71644
9.8 CRITICAL

An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions …

Sep 11, 2026
CVE-2026-84390
9.8 CRITICAL

A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access …

Sep 11, 2026
CVE-2026-80462
10.0 CRITICAL

A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate …

Sep 11, 2026
CVE-2026-89259
9.8 CRITICAL

Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list …

Sep 11, 2026
CVE-2026-86793
9.8 CRITICAL

SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are …

Sep 11, 2026
CVE-2026-14563
9.8 CRITICAL

The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, …

Sep 11, 2026
CVE-2026-14560
10.0 CRITICAL

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated …

Sep 11, 2026
CVE-2026-14559
9.8 CRITICAL

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, …

Sep 11, 2026
CVE-2026-8778
9.8 CRITICAL

The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing …

Sep 11, 2026
CVE-2026-82107
9.6 CRITICAL

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper …

Sep 10, 2026
CVE-2026-82100
9.6 CRITICAL

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal …

Sep 10, 2026
CVE-2026-81204
9.8 CRITICAL

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.

Sep 10, 2026
CVE-2026-80424
9.1 CRITICAL

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.

Sep 10, 2026
CVE-2026-79724
9.8 CRITICAL

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in …

Sep 10, 2026
CVE-2026-78573
9.8 CRITICAL

IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.

Sep 10, 2026
CVE-2026-71640
9.1 CRITICAL

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe vehicle motion via improper handling of expired trajectory data in the replanning …

Sep 10, 2026
CVE-2026-45764
9.1 CRITICAL

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a protocol change while …

Sep 10, 2026
CVE-2026-19646
9.1 CRITICAL

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to …

Sep 10, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.