CVE Database

9856+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-8476
9.9 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() …

Jul 17, 2026
CVE-2026-63030
9.8 CRITICAL KEV

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query …

Jul 17, 2026
CVE-2026-52199
9.1 CRITICAL

An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component

Jul 17, 2026
CVE-2026-42168
9.1 CRITICAL

django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model. These fields are passed directly to …

Jul 17, 2026
CVE-2026-36669
9.8 CRITICAL

An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) to the web-accessible …

Jul 17, 2026
CVE-2026-15091
9.3 CRITICAL

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web …

Jul 17, 2026
CVE-2025-51677
9.1 CRITICAL

An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can …

Jul 17, 2026
CVE-2026-9135
9.9 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that …

Jul 17, 2026
CVE-2026-9103
9.8 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint …

Jul 17, 2026
CVE-2026-9202
9.8 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created …

Jul 17, 2026
CVE-2026-9198
9.8 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via …

Jul 17, 2026
CVE-2026-8297
9.8 CRITICAL

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab …

Jul 17, 2026
CVE-2026-54496
9.3 CRITICAL

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base scalar …

Jul 17, 2026
CVE-2026-12694
9.1 CRITICAL

Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 …

Jul 17, 2026
CVE-2026-12693
9.4 CRITICAL

Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video …

Jul 17, 2026
CVE-2026-12692
9.8 CRITICAL

Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

Jul 17, 2026
CVE-2026-60024
9.8 CRITICAL

The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.

Jul 17, 2026
CVE-2026-51080
9.8 CRITICAL

libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.

Jul 17, 2026
CVE-2024-23564
9.1 CRITICAL

HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and …

Jul 17, 2026
CVE-2026-9810
9.8 CRITICAL

The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator …

Jul 17, 2026
CVE-2026-15982
9.8 CRITICAL

The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up …

Jul 17, 2026
CVE-2026-62241
9.1 CRITICAL

clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET …

Jul 17, 2026
CVE-2026-14956
9.8 CRITICAL

The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of …

Jul 17, 2026
CVE-2026-57075
9.1 CRITICAL

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec. The base64 decoder in the bundled libsyck indexes …

Jul 16, 2026
CVE-2026-53412
9.8 CRITICAL

Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user …

Jul 16, 2026
CVE-2026-44180
9.8 CRITICAL

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Versions 2.0.0rc1 and above prior to 3.3.0 …

Jul 16, 2026
CVE-2026-38158
9.8 CRITICAL

A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL statements.

Jul 16, 2026
CVE-2026-63089
9.3 CRITICAL

WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers to recover WireGuard …

Jul 16, 2026
CVE-2026-46512
9.9 CRITICAL

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, dest, url, extension, code, and file, …

Jul 16, 2026
CVE-2026-45336
10.0 CRITICAL

HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier, app.py assigns a hard-coded Flask …

Jul 16, 2026
CVE-2026-63087
9.8 CRITICAL

Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the …

Jul 16, 2026
CVE-2026-57074
9.1 CRITICAL

XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element …

Jul 16, 2026
CVE-2026-57073
9.1 CRITICAL

HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element …

Jul 16, 2026
CVE-2026-46621
9.1 CRITICAL

Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using …

Jul 16, 2026
CVE-2026-46562
9.8 CRITICAL

Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed without a …

Jul 16, 2026
CVE-2026-45568
9.1 CRITICAL

zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL …

Jul 16, 2026
CVE-2026-44632
9.1 CRITICAL

Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which dynamically compiled …

Jul 16, 2026
CVE-2026-3031
9.8 CRITICAL

Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg 0.9.0 that was last updated in 2004. Epeg …

Jul 16, 2026
CVE-2026-45695
9.8 CRITICAL

Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to 0.23.0, …

Jul 16, 2026
CVE-2026-14890
9.1 CRITICAL

SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, …

Jul 16, 2026
CVE-2026-11386
9.0 CRITICAL

An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) …

Jul 16, 2026
CVE-2023-49900
9.8 CRITICAL

An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.

Jul 16, 2026
CVE-2023-49899
9.8 CRITICAL

An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.

Jul 16, 2026
CVE-2026-22752
9.6 CRITICAL

Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through …

Jul 16, 2026
CVE-2026-12492
9.8 CRITICAL

The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user …

Jul 16, 2026
CVE-2026-15013
9.8 CRITICAL

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up …

Jul 16, 2026
CVE-2026-55652
9.8 CRITICAL

Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the client-supplied X-Forwarded-For header before …

Jul 15, 2026
CVE-2026-54458
9.6 CRITICAL

WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin. Any unauthenticated …

Jul 15, 2026
CVE-2026-52891
9.9 CRITICAL

Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec() for …

Jul 15, 2026
CVE-2026-30623
9.8 CRITICAL

LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON …

Jul 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.