CVE Database

45217+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-51675
7.5 HIGH

An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate update of program counter (PC) values when SPR changes can lead to a Denial …

Aug 26, 2026
CVE-2026-79938
7.6 HIGH

Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, …

Aug 26, 2026
CVE-2026-77652
7.8 HIGH

A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer. In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette …

Aug 26, 2026
CVE-2026-74770
8.8 HIGH

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low …

Aug 26, 2026
CVE-2026-68863
7.5 HIGH

Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading …

Aug 26, 2026
CVE-2026-68861
8.8 HIGH

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low …

Aug 26, 2026
CVE-2026-46369
7.5 HIGH

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound …

Aug 26, 2026
CVE-2026-26449
7.5 HIGH

In Stomper 5e2741e when a client sends a SEND frame missing the destination header field, the server triggers a null pointer dereference (or access to …

Aug 26, 2026
CVE-2026-26447
7.5 HIGH

Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeatedly issues SUBSCRIBE commands for the same destination over one connection and then closes that …

Aug 26, 2026
CVE-2026-26446
7.5 HIGH

Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was already closed by the peer, …

Aug 26, 2026
CVE-2026-71171
7.2 HIGH

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in …

Aug 26, 2026
CVE-2026-36851
7.5 HIGH

Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.

Aug 26, 2026
CVE-2025-61164
7.5 HIGH

Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.

Aug 26, 2026
CVE-2025-61162
7.5 HIGH

Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted request to the /api/internal/v1/users/{{USER_ID}} endpoint

Aug 26, 2026
CVE-2026-58474
8.8 HIGH

whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to …

Aug 26, 2026
CVE-2026-47841
7.4 HIGH

An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store. Spring Security 7.1.0 Spring …

Aug 26, 2026
CVE-2026-47836
7.2 HIGH

The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config …

Aug 26, 2026
CVE-2025-56798
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication …

Aug 26, 2026
CVE-2025-29419
7.1 HIGH

CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.

Aug 26, 2026
CVE-2026-32258
8.1 HIGH

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor …

Aug 26, 2026
CVE-2026-32257
8.1 HIGH

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings …

Aug 26, 2026
CVE-2020-15878
8.8 HIGH

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a …

Aug 26, 2026
CVE-2020-15876
8.8 HIGH

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a …

Aug 26, 2026
CVE-2020-15874
8.8 HIGH

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the …

Aug 26, 2026
CVE-2026-81036
8.1 HIGH

Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success …

Aug 26, 2026
CVE-2026-81035
8.1 HIGH

Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises the caller with the team-access helper, which returns true …

Aug 26, 2026
CVE-2026-81031
7.2 HIGH

IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the request. The update handler in backend/src/controllers/middlewaresControllers/createUserController/updatePassword.js resolves …

Aug 26, 2026
CVE-2026-81029
8.1 HIGH

OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the …

Aug 26, 2026
CVE-2026-81027
8.5 HIGH

one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a specific channel either through a suffix …

Aug 26, 2026
CVE-2026-80427
8.4 HIGH

bestzip builds the argument list for the system zip utility without separating options from operands. The destination archive path and the caller-supplied source paths are …

Aug 26, 2026
CVE-2026-80426
7.1 HIGH

FiftyOne renders a dataset field's description as markup. The sidebar field-information component at app/packages/core/src/components/FieldLabelAndInfo/index.tsx passes the description string to React's dangerouslySetInnerHTML, and no layer between …

Aug 26, 2026
CVE-2026-80588
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: mptcp: reclaim forward-allocated memory on RX path errors After commit 9db5b3cec4ec ("mptcp: borrow forward memory …

Aug 26, 2026
CVE-2026-80584
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: s390/qeth: validate user buffer length in SNMP and ARP query ioctls qeth_snmp_command() and qeth_l3_arp_query() allocate …

Aug 26, 2026
CVE-2026-80583
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses The "DEC0 MODE" to "DEC7 MODE" controls are …

Aug 26, 2026
CVE-2026-80582
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/shmem_helper: Check VMA boundaries for PMD mappings In the ->huge_fault handler do not install a …

Aug 26, 2026
CVE-2026-80580
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: fbdev: bound mode sysfs output to the sysfs buffer mode_string() uses snprintf() which can return …

Aug 26, 2026
CVE-2026-80579
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: fbdev: clear fb_info->mode before deleting a videomode fb_set_var() can delete a mode from info->modelist when …

Aug 26, 2026
CVE-2026-80578
7.3 HIGH

In the Linux kernel, the following vulnerability has been resolved: fbdev: core: Fix pointer desynchronization in fb_io_read() In fb_io_read(), if copy_to_user() performs a partial copy …

Aug 26, 2026
CVE-2026-80576
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject oversized IBs with per-ring packet limits On GFX rings, amdgpu_cs_p2_ib() passed user-supplied ib_bytes …

Aug 26, 2026
CVE-2026-80575
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Input: cs40l50-vibra - validate custom data from user space cs40l50_add() copies the custom data of …

Aug 26, 2026
CVE-2026-80574
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet Make finger2 (and also finger1) unsigned, so …

Aug 26, 2026
CVE-2026-80572
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Input: byd - synchronize timer deletion before freeing private data byd_disconnect() uses timer_delete() before freeing …

Aug 26, 2026
CVE-2026-80570
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - zero report size on F54 work error In rmi_f54_work(), if an error …

Aug 26, 2026
CVE-2026-80569
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer rmi_f54_work() reads a …

Aug 26, 2026
CVE-2026-80568
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - block s_input when F54 queue is busy Changing the input (diagnostic report …

Aug 26, 2026
CVE-2026-80565
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: crypto: qce - fix error path in devm_qce_register_algs If ops->register_algs() fails, the error path repeatedly …

Aug 26, 2026
CVE-2026-80560
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: openrisc: signal: do not restore privileged SR bits on sigreturn restore_sigcontext() copies the whole supervision …

Aug 26, 2026
CVE-2026-80559
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Input: sur40 - fix input device registration ordering In sur40_probe(), input_register_device() was previously called early …

Aug 26, 2026
CVE-2026-80556
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition In atmci_probe, &host->bh_work is bound …

Aug 26, 2026
CVE-2026-80555
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Free all memory if cp_init() fails The routine cp_free() is called to unpin/free any …

Aug 26, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.