CVE Database

132006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-82779
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series. If this vulnerability is exploited, an …

Sep 14, 2026
CVE-2026-82778
4.3 MEDIUM

An exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on this product may allow a remote unauthenticated …

Sep 14, 2026
CVE-2026-82777
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an …

Sep 14, 2026
CVE-2026-82776
6.1 MEDIUM

Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

Sep 14, 2026
CVE-2026-82775
4.3 MEDIUM

An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this …

Sep 14, 2026
CVE-2026-82774
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. …

Sep 14, 2026
CVE-2026-82773
6.1 MEDIUM

Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed …

Sep 14, 2026
CVE-2026-82772
8.8 HIGH

Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program …

Sep 14, 2026
CVE-2026-82771
5.4 MEDIUM

Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

Sep 14, 2026
CVE-2026-82770
8.8 HIGH

Buffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program …

Sep 14, 2026
CVE-2026-82769
5.4 MEDIUM

Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

Sep 14, 2026
CVE-2026-82768
8.1 HIGH

Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who …

Sep 14, 2026
CVE-2026-82767
5.2 MEDIUM

Cross-site scripting vulnerability exists in SGA1000. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

Sep 14, 2026
CVE-2026-82766
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If this vulnerability is exploited, an arbitrary OS …

Sep 14, 2026
CVE-2026-82765
8.1 HIGH

Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be …

Sep 14, 2026
CVE-2026-82764
4.3 MEDIUM

Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page while logged in to the affected product, unintended …

Sep 14, 2026
CVE-2026-82763
5.4 MEDIUM

Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on …

Sep 14, 2026
CVE-2026-82762
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If …

Sep 14, 2026
CVE-2026-71198

In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike the web-download import …

Sep 14, 2026
CVE-2026-68955
7.8 HIGH

The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when …

Sep 14, 2026
CVE-2026-25832
3.7 LOW

In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.

Sep 14, 2026
CVE-2025-26790
3.7 LOW

Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memory read during processing of a document file by …

Sep 14, 2026
CVE-2024-23176
5.4 MEDIUM

An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.

Sep 14, 2026
CVE-2023-51769
6.1 MEDIUM

Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.

Sep 14, 2026
CVE-2023-50462
5.3 MEDIUM

An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to verify whether a specified content element identifier …

Sep 14, 2026
CVE-2023-50461
8.8 HIGH

An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated …

Sep 14, 2026
CVE-2023-50460
5.4 MEDIUM

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions …

Sep 14, 2026
CVE-2023-50459
5.4 MEDIUM

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An …

Sep 14, 2026
CVE-2026-90687
6.3 MEDIUM

A vulnerability was determined in GPAC up to f1219cde. This vulnerability affects the function gf_node_changed_internal of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation …

Sep 14, 2026
CVE-2026-90686
5.3 MEDIUM

A vulnerability was found in GPAC up to f1219cde. This affects the function gf_bt_report of the file scene_manager/loader_bt.c of the component MP4Box. The manipulation results …

Sep 14, 2026
CVE-2026-90685
2.8 LOW

A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component …

Sep 14, 2026
CVE-2026-16726

Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows attackers to stop Windows.

Sep 14, 2026
CVE-2023-46273
8.8 HIGH

Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.

Sep 14, 2026
CVE-2023-46035
5.9 MEDIUM

The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.

Sep 14, 2026
CVE-2023-45858
8.6 HIGH

A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.

Sep 14, 2026
CVE-2023-45023
4.2 MEDIUM

The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.

Sep 14, 2026
CVE-2023-40772
4.3 MEDIUM

A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component.

Sep 14, 2026
CVE-2023-37366
2.8 LOW

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, …

Sep 14, 2026
CVE-2023-37253
3.1 LOW

An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables.

Sep 14, 2026
CVE-2026-90684
2.8 LOW

A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component …

Sep 14, 2026
CVE-2026-90683
3.3 LOW

A vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation …

Sep 14, 2026
CVE-2026-90682
5.3 MEDIUM

A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP …

Sep 14, 2026
CVE-2026-90681
3.3 LOW

A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. …

Sep 14, 2026
CVE-2023-37252
3.1 LOW

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.

Sep 14, 2026
CVE-2023-34854
6.6 MEDIUM

HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.

Sep 14, 2026
CVE-2023-32803
7.5 HIGH

The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue …

Sep 14, 2026
CVE-2023-32778
3.3 LOW

An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload.

Sep 14, 2026
CVE-2023-29377
6.6 MEDIUM

An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is …

Sep 14, 2026
CVE-2023-28148
7.2 HIGH

A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.

Sep 14, 2026
CVE-2023-24291
2.9 LOW

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.

Sep 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.