CVE Database

57293+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-0187
6.7 MEDIUM

In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation …

Sep 15, 2026
CVE-2026-0186
6.7 MEDIUM

In ac_init_one_sswrp of init.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation …

Sep 15, 2026
CVE-2026-0183
4.4 MEDIUM

In CPM, there is a possible information disclosure due to a confused deputy. This could lead to local information disclosure with System execution privileges needed. …

Sep 15, 2026
CVE-2026-0179
6.7 MEDIUM

In Bootloader, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution …

Sep 15, 2026
CVE-2026-0177
4.4 MEDIUM

In do_sss_aes_gcm_256_op of crypto-aes.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Sep 15, 2026
CVE-2026-82837
5.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions …

Sep 15, 2026
CVE-2026-81237
6.5 MEDIUM

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading …

Sep 15, 2026
CVE-2026-56831
6.5 MEDIUM

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes …

Sep 15, 2026
CVE-2026-56830
6.5 MEDIUM

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Media.php without the edit_products authorization check …

Sep 15, 2026
CVE-2026-55375
5.3 MEDIUM

canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, OAuth2Request::getQueryParams() places app_id, app_secret, refresh_token, and code in the …

Sep 15, 2026
CVE-2026-55374
4.8 MEDIUM

canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, Request::buildRequestUrl() joins values returned by Request::getPathVariables() without encoding individual …

Sep 15, 2026
CVE-2026-55226
5.4 MEDIUM

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, deploying only …

Sep 15, 2026
CVE-2026-54689
6.3 MEDIUM

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, the web_url_read URL policy …

Sep 15, 2026
CVE-2026-54688
6.5 MEDIUM

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, web_url_read passes a caller-supplied …

Sep 15, 2026
CVE-2026-54050
6.5 MEDIUM

Sakai is a Collaboration and Learning Environment (CLE). From 23.0 until 23.5 and 25.3, the DELETE /api/users/{userId}/profile/image endpoint allows an authenticated user to delete another …

Sep 15, 2026
CVE-2026-53954
4.3 MEDIUM

Bugsink is a self-hosted error tracking tool. Prior to version 2.2.2, Bugsink stores every set of custom tags supplied with an incoming event, allowing a …

Sep 15, 2026
CVE-2026-48785
4.8 MEDIUM

Apptainer is an open source container platform. Prior to version 1.5.1, Image.AuthorizedPath applies plain string-prefix matching to the limit container paths directive in apptainer.conf, so …

Sep 15, 2026
CVE-2026-39038
6.1 MEDIUM

BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (trufflebox-ui) in GenericNumerixTable.jsx.

Sep 15, 2026
CVE-2026-12910
5.4 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain …

Sep 15, 2026
CVE-2026-12751
5.4 MEDIUM

IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed …

Sep 15, 2026
CVE-2026-12750
6.4 MEDIUM

IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the …

Sep 15, 2026
CVE-2026-12749
6.4 MEDIUM

IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the …

Sep 15, 2026
CVE-2026-12742
5.4 MEDIUM

IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls.

Sep 15, 2026
CVE-2026-11918
5.4 MEDIUM

IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mechanisms due to incomplete recursive inspection of nested payload …

Sep 15, 2026
CVE-2026-11864
6.5 MEDIUM

IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and …

Sep 15, 2026
CVE-2026-91855
5.3 MEDIUM

A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality of the file lib/pfcp/handler.c of the …

Sep 15, 2026
CVE-2026-91854
4.3 MEDIUM

A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the file main/reg.php. Such manipulation of the argument desc …

Sep 15, 2026
CVE-2026-79705
4.5 MEDIUM

A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks …

Sep 15, 2026
CVE-2026-79699
4.4 MEDIUM

A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory …

Sep 15, 2026
CVE-2026-55863
5.3 MEDIUM

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, …

Sep 15, 2026
CVE-2026-54561
6.2 MEDIUM

MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_import in src/index.ts passes the caller-controlled filePath …

Sep 15, 2026
CVE-2026-54503
4.3 MEDIUM

plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME type. Prior to 2.0.2, 3.0.2, and 4.0.1, depending on …

Sep 15, 2026
CVE-2026-91992
5.9 MEDIUM

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive …

Sep 15, 2026
CVE-2026-91991
5.4 MEDIUM

Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword …

Sep 15, 2026
CVE-2026-91987
6.5 MEDIUM

atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table. Attackers can …

Sep 15, 2026
CVE-2026-91986
5.4 MEDIUM

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can …

Sep 15, 2026
CVE-2026-91984
4.3 MEDIUM

Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project. Authenticated attackers can insert task position rows into …

Sep 15, 2026
CVE-2026-91983
4.3 MEDIUM

Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters. Attackers with limited …

Sep 15, 2026
CVE-2026-91982
4.3 MEDIUM

Vikunja before 2.6.0 continues to expose the raw TOTP shared secret after enrollment through the GET /api/v1/user/settings/totp and /api/v1/user/settings/totp/qrcode endpoints without re-authentication. Attackers with a …

Sep 15, 2026
CVE-2026-91981
4.3 MEDIUM

Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints. Attackers with a read-only share link can enumerate …

Sep 15, 2026
CVE-2026-91980
4.3 MEDIUM

vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enumerate all teams and members. Attackers can attach …

Sep 15, 2026
CVE-2026-91979
6.5 MEDIUM

Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service. Attackers can upload highly compressed files …

Sep 15, 2026
CVE-2026-91971
6.5 MEDIUM

Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing authenticated users to upload crafted images that decode to …

Sep 15, 2026
CVE-2026-91970
6.5 MEDIUM

Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aggregate memory budgets during migration jobs. Authenticated attackers …

Sep 15, 2026
CVE-2026-91969
6.5 MEDIUM

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality. Authenticated attackers can upload …

Sep 15, 2026
CVE-2026-91968
6.5 MEDIUM

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers …

Sep 15, 2026
CVE-2026-91967
5.0 MEDIUM

AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL function that issues get_headers() calls guarded only by format validation. Authenticated users …

Sep 15, 2026
CVE-2026-91966
5.8 MEDIUM

AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to …

Sep 15, 2026
CVE-2026-91963
6.5 MEDIUM

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB …

Sep 15, 2026
CVE-2026-91962
6.3 MEDIUM

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values …

Sep 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.