CVE Database

47191+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-42797
4.9 MEDIUM

Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression …

May 25, 2026
CVE-2026-9464
4.7 MEDIUM

A vulnerability has been found in YunaiV yudao-cloud 2026.03. This affects the function IotDataSinkHttpConfig of the file /admin-api/iot/data-sink/create of the component Admin API Endpoint. Such …

May 25, 2026
CVE-2026-9078
5.4 MEDIUM

Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname could visually …

May 25, 2026
CVE-2026-47076
6.5 MEDIUM

Interpretation Conflict vulnerability in benoitc hackney allows Server Side Request Forgery. hackney_url:normalize/2 URL-decodes the host component after the URL has been parsed into a #hackney_url{} …

May 25, 2026
CVE-2026-47070
6.1 MEDIUM

Sensitive Data Exposure vulnerability in benoitc hackney allows Retrieve Embedded Sensitive Data. The HTTP/3 redirect handler in src/hackney_h3.erl passes the original request headers unchanged to …

May 25, 2026
CVE-2026-47069
5.3 MEDIUM

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in benoitc hackney allows HTTP Response Splitting. The hackney_cookie:setcookie/3 function in src/hackney_cookie.erl validates the Name and Value …

May 25, 2026
CVE-2018-25378
6.2 MEDIUM

Notebook Pro 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the …

May 25, 2026
CVE-2018-25370
5.3 MEDIUM

Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows low-privilege users to increase their permissions by exploiting improper origin checking. Attackers can craft malicious …

May 25, 2026
CVE-2018-25369
6.2 MEDIUM

Visual Ping 0.8.0.0 contains a buffer overflow vulnerability in input field handling that allows local attackers to crash the application by supplying oversized data. Attackers …

May 25, 2026
CVE-2018-25367
6.2 MEDIUM

NASA openVSP 3.16.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the geometry …

May 25, 2026
CVE-2018-25363
4.3 MEDIUM

Twitter-Clone 1 contains a cross-site request forgery vulnerability that allows remote attackers to force victims to delete posts by crafting malicious HTML forms. Attackers can …

May 25, 2026
CVE-2018-25361
6.8 MEDIUM

Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove passcodes by injecting pre-encrypted database entries using a constant …

May 25, 2026
CVE-2026-9451
6.3 MEDIUM

A weakness has been identified in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /process/applyleaveprocess.php. This manipulation …

May 25, 2026
CVE-2026-9450
6.3 MEDIUM

A security flaw has been discovered in code-projects Employee Management System 1.0. Affected is an unknown function of the file /psubmit.php. The manipulation of the …

May 25, 2026
CVE-2026-9449
6.3 MEDIUM

A vulnerability was identified in code-projects Employee Management System 1.0. This impacts an unknown function of the file /changepassemp.php. The manipulation leads to sql injection. …

May 25, 2026
CVE-2026-9448
4.3 MEDIUM

A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown function of the file /applyleave.php. Executing a manipulation of the argument …

May 25, 2026
CVE-2026-46745
5.3 MEDIUM

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to …

May 25, 2026
CVE-2026-9446
4.7 MEDIUM

A vulnerability has been found in SourceCodester Simple POS and Inventory System 1.0. The affected element is an unknown function of the file /admin/edit_customer.php. Such …

May 25, 2026
CVE-2026-9445
6.3 MEDIUM

A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file /admin/addproduct.php of the component …

May 25, 2026
CVE-2026-9444
4.7 MEDIUM

A vulnerability was detected in SourceCodester Simple POS and Inventory System 1.0. This issue affects the function delete of the file /admin/deleteproduct.php of the component …

May 25, 2026
CVE-2026-9441
6.3 MEDIUM

A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formiNICbasic of the file /goform/formiNICbasic of the component …

May 25, 2026
CVE-2026-9440
6.3 MEDIUM

A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formAccept of the file /goform/formAccept of the component POST Request …

May 25, 2026
CVE-2026-9439
6.3 MEDIUM

A vulnerability was determined in Edimax BR-6675nD 1.12. Affected is the function stainfo of the file /goform/stainfo. This manipulation of the argument interface causes command …

May 25, 2026
CVE-2026-9438
5.4 MEDIUM

A vulnerability was found in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This impacts an unknown function of the file courseDel.php. The manipulation of the argument ID results in …

May 25, 2026
CVE-2026-9437
6.3 MEDIUM

A vulnerability has been found in DTStack Taier 1.4.0. This affects the function Runtime.exec of the component REST API. The manipulation of the argument sqlText …

May 25, 2026
CVE-2026-4915
6.5 MEDIUM

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to filter nil elements from outgoing webhook attachment payloads before …

May 25, 2026
CVE-2026-45249
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic. This issue affects Apache ECharts: from before 6.1.0. In …

May 25, 2026
CVE-2026-41863
6.5 MEDIUM

Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to …

May 25, 2026
CVE-2026-9424
6.3 MEDIUM

A weakness has been identified in Edimax EW-7438RPn 1.31. The affected element is the function formWlanMP of the file /goform/formWlanMP of the component Content-Type Handler. …

May 25, 2026
CVE-2026-9423
4.7 MEDIUM

A security flaw has been discovered in Edimax BR-6675nD 1.12. Impacted is the function mp of the file /goform/mp of the component POST Request Handler. …

May 25, 2026
CVE-2026-9420
6.3 MEDIUM

A vulnerability was found in KLiK SocialMediaWebsite 1.0. This affects an unknown part of the component HTTP GET Request Parameter Handler. The manipulation results in …

May 25, 2026
CVE-2026-9419
4.3 MEDIUM

A vulnerability has been found in code-projects Employee Management System 1.0. Affected by this issue is some unknown functionality of the file /empproject.php. The manipulation …

May 25, 2026
CVE-2026-9418
4.3 MEDIUM

A flaw has been found in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /changepassemp.php. Executing a …

May 25, 2026
CVE-2026-9417
4.3 MEDIUM

A vulnerability was detected in code-projects Employee Management System 1.0. Affected is an unknown function of the file /myprofileup.php. Performing a manipulation of the argument …

May 25, 2026
CVE-2026-9416
4.3 MEDIUM

A security vulnerability has been detected in code-projects Employee Management System 1.0. This impacts an unknown function of the file /myprofile.php. Such manipulation of the …

May 25, 2026
CVE-2026-9415
4.3 MEDIUM

A weakness has been identified in code-projects Employee Management System 1.0. This affects an unknown function of the file /eloginwel.php. This manipulation of the argument …

May 25, 2026
CVE-2026-9413
4.3 MEDIUM

A vulnerability was identified in SourceCodester Indian Invoicing System 1.0. The affected element is an unknown function of the file /Invoicing/category.php. The manipulation of the …

May 25, 2026
CVE-2026-9412
6.3 MEDIUM

A vulnerability was determined in SourceCodester Indian Invoicing System 1.0. Impacted is an unknown function of the component Backend Endpoint. Executing a manipulation can lead …

May 25, 2026
CVE-2026-9411
6.3 MEDIUM

A vulnerability was found in SourceCodester Indian Invoicing System 1.0. This issue affects some unknown processing of the file /Invoicing/IGST_Invoice.php of the component Invoice Generation …

May 25, 2026
CVE-2026-9410
4.3 MEDIUM

A vulnerability has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This vulnerability affects unknown code of the file /profile of the component Profile Workflow. …

May 25, 2026
CVE-2026-9409
4.3 MEDIUM

A flaw has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This affects an unknown part of the file /user of the component User Management …

May 25, 2026
CVE-2026-9402
6.3 MEDIUM

A vulnerability was found in Edimax BR-6675nD 1.12. The affected element is the function formWlanMP of the file /goform/formWlanMP of the component POST Request Handler. …

May 24, 2026
CVE-2026-9400
6.3 MEDIUM

A flaw has been found in Edimax BR-6675nD 1.12. This issue affects the function formUSBStorage of the file /goform/formUSBStorage of the component POST Request Handler. …

May 24, 2026
CVE-2026-9379
6.3 MEDIUM

A weakness has been identified in Edimax BR-6675nD 1.12. This impacts the function formWpsStart of the file /goform/formWpsStart of the component POST Request Handler. This …

May 24, 2026
CVE-2026-9378
6.3 MEDIUM

A security flaw has been discovered in Edimax BR-6675nD 1.12. This affects the function formHwSet of the file /goform/formHwSet of the component POST Request Handler. …

May 24, 2026
CVE-2026-9376
6.3 MEDIUM

A vulnerability was determined in JPress up to 1.0.3. The affected element is an unknown function of the file /ucenter/article/doWriteSave of the component UCenter Article …

May 24, 2026
CVE-2026-9374
6.3 MEDIUM

A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. Impacted is the function FileUploadUtils.upload of the file /common/upload of the component Common Upload Endpoint. …

May 24, 2026
CVE-2026-9371
5.6 MEDIUM

A security vulnerability has been detected in ItzCrazyKns Vane up to 1.12.1. Affected by this issue is some unknown functionality of the file route.ts of …

May 24, 2026
CVE-2026-9369
5.3 MEDIUM

A security flaw has been discovered in NousResearch hermes-agent 2026.4.23. Affected is the function _discover_dashboard_plugins of the file hermes_cli/web_server.py of the component CLI web-dashboard Interface. …

May 24, 2026
CVE-2026-9365
5.6 MEDIUM

A vulnerability has been found in Ettercap up to 0.8.3. The affected element is the function FUNC_DECODER of the file src/dissectors/ec_gg.c of the component GG …

May 24, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.