CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-16724
4.5 MEDIUM

IBM Virtualization Management Interface FW1110.00 through FW1110.30, FW1120.00 through FW1120.00, and FW1060.00 through FW1060.80 is affected by a vulnerability in the Virtualization Management Interface (VMI). …

Aug 19, 2026
CVE-2026-55703
4.3 MEDIUM

Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id} and read maintenance records for assets in the same …

Aug 19, 2026
CVE-2026-55519
5.4 MEDIUM

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permission can delete files attached to assets outside …

Aug 19, 2026
CVE-2026-55482
6.3 MEDIUM

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/BulkAssetsController.php update() to submit company_id directly without Company::getIdForCurrentUser(), allowing assets to …

Aug 19, 2026
CVE-2026-50550
5.8 MEDIUM

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users can reset a superadmin's two-factor authentication through app/Http/Controllers/Api/UsersController.php …

Aug 19, 2026
CVE-2026-49976
6.5 MEDIUM

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update mode to overwrite the email …

Aug 19, 2026
CVE-2026-49870
5.9 MEDIUM

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or attempt counter, allowing an attacker with valid …

Aug 19, 2026
CVE-2026-19321
6.7 MEDIUM

Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware. An attacker with service access …

Aug 19, 2026
CVE-2026-18681
6.8 MEDIUM

IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP firmware update process. …

Aug 19, 2026
CVE-2026-16938
6.9 MEDIUM

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in access controls over privileged …

Aug 19, 2026
CVE-2026-63117
6.5 MEDIUM

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated RDP client can advertise DVI ADPCM with nBlockAlign equal to …

Aug 19, 2026
CVE-2026-55564
5.4 MEDIUM

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, the glyph_cache_get function in libfreerdp/cache/glyph.c checks whether index is greater than cache->number …

Aug 19, 2026
CVE-2026-19653
6.5 MEDIUM

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to improper handling …

Aug 19, 2026
CVE-2026-18874
6.2 MEDIUM

A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Markup Language) code into the OpenShift Lifecycle Manager …

Aug 19, 2026
CVE-2026-75145
5.8 MEDIUM

FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The OBU size is cast to long before comparison …

Aug 19, 2026
CVE-2026-49392
5.3 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in …

Aug 19, 2026
CVE-2026-44256
5.3 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.4.0 until 4.14.6 and 5.0.0-beta2, api/api/middlewares.py decodes the Basic …

Aug 19, 2026
CVE-2026-44255
5.3 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AuthenticationManager.check_user() in framework/wazuh/rbac/orm.py performs …

Aug 19, 2026
CVE-2026-20327
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack …

Aug 19, 2026
CVE-2026-20314
5.0 MEDIUM

A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to …

Aug 19, 2026
CVE-2026-20302
6.1 MEDIUM

A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to the USB port on an affected …

Aug 19, 2026
CVE-2026-20232
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an authenticated, remote attacker to conduct a stored …

Aug 19, 2026
CVE-2026-20177
5.3 MEDIUM

A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an unauthenticated, remote attacker to cause the …

Aug 19, 2026
CVE-2026-62671
5.4 MEDIUM

Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.regenerate2FASecret task accepts a top-level …

Aug 19, 2026
CVE-2026-62670
6.3 MEDIUM

Grav Flex Objects Plugin allows you to build custom collections of objects. Prior to 1.4.3, the Grav Flex Objects Admin Next API requireFlexPermission() method in …

Aug 19, 2026
CVE-2026-61842
6.5 MEDIUM

Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to return the raw configuration object and permits json_encode, …

Aug 19, 2026
CVE-2026-61690
6.5 MEDIUM

Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Filesystem/ZipArchiver.php passes archives to ZipArchive::extractTo() without enforcing the system.gpm.archive uncompressed-size, file-count, or nesting-depth …

Aug 19, 2026
CVE-2026-61607
4.6 MEDIUM

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.2, the Grav API …

Aug 19, 2026
CVE-2026-44254
5.3 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 1.0.0 until 4.14.6 and 5.0.0-beta2, HandleSecureMessage() in src/remoted/secure.c passes …

Aug 19, 2026
CVE-2026-44253
4.9 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 3.9.0 until 4.14.5 and 5.0.0-beta2, the Wazuh cluster protocol …

Aug 19, 2026
CVE-2026-76614
4.3 MEDIUM

OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function. The archrestore_sel POST parameter is passed to the archive restore handler …

Aug 19, 2026
CVE-2026-67268
6.5 MEDIUM

Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access …

Aug 19, 2026
CVE-2026-67267
5.5 MEDIUM

Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker …

Aug 19, 2026
CVE-2026-67266
5.5 MEDIUM

Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, …

Aug 19, 2026
CVE-2026-56796
6.6 MEDIUM

Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local …

Aug 19, 2026
CVE-2026-54793
4.6 MEDIUM

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with …

Aug 19, 2026
CVE-2026-53452
5.3 MEDIUM

Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated configure-sdr Socket.IO command …

Aug 19, 2026
CVE-2026-50149
6.5 MEDIUM

Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, when an `HTTPProxy` is configured with incompatible combination of both `.spec.virtualhost.tls.enableFallbackCertificate: …

Aug 19, 2026
CVE-2026-40509
4.3 MEDIUM

OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer. The web_path GET parameter in the DICOM viewer page is embedded unsanitized …

Aug 19, 2026
CVE-2026-40508
5.4 MEDIUM

OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal template import handler that allows authenticated attackers with Forms Administration permissions to …

Aug 19, 2026
CVE-2026-40507
6.1 MEDIUM

OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal template import handler. The templateHtml GET parameter is reflected into the page …

Aug 19, 2026
CVE-2026-32802
5.3 MEDIUM

Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this …

Aug 19, 2026
CVE-2026-15961
5.2 MEDIUM

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 IBM PowerVM could allow a local attacker to obtain sensitive information or cause a …

Aug 19, 2026
CVE-2026-76239
6.3 MEDIUM

Stigmem before 0.9.0a11 fails to validate the delivery_address parameter when creating webhook subscriptions, allowing authenticated users to specify internal loopback and private network destinations. Attackers …

Aug 19, 2026
CVE-2026-76233
6.7 MEDIUM

Renovate versions from 39.53.0 before 40.33.0 contain a command injection vulnerability in the gleam manager where the depName parameter is appended to gleam deps update …

Aug 19, 2026
CVE-2026-76232
6.7 MEDIUM

Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv3 manager where the repository parameter is appended to helm registry login …

Aug 19, 2026
CVE-2026-76231
6.7 MEDIUM

Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where user-provided dependency names are appended to install and uninstall …

Aug 19, 2026
CVE-2026-76230
6.7 MEDIUM

Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm manager where user-provided packageName values are appended to npm install commands …

Aug 19, 2026
CVE-2026-76229
6.7 MEDIUM

Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability in the kustomize manager where user-provided chart names are appended to helm pull …

Aug 19, 2026
CVE-2026-76228
6.7 MEDIUM

Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) contain a command injection vulnerability in Gradle Wrapper artifact handling. When Renovate processes Gradle …

Aug 19, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.