CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-76227
5.5 MEDIUM

Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renovate/renovate, mend/renovate-ce, renovate-ee-server, renovate-ee-worker >=13.3.0 <13.6.0), fail to restrict environment …

Aug 19, 2026
CVE-2026-76226
6.3 MEDIUM

Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazelisk managers when using lockFileMaintenance. Attackers can execute arbitrary code …

Aug 19, 2026
CVE-2026-76217
6.5 MEDIUM

GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and …

Aug 19, 2026
CVE-2026-76215
5.3 MEDIUM

phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility checks before returning child resources including comments and attachments. Unauthenticated attackers can retrieve restricted comment text, …

Aug 19, 2026
CVE-2026-76212
5.3 MEDIUM

phpMyFAQ before 4.1.7, when configured to use PostgreSQL via the native pgsql PHP extension, declares an incorrect LIKE ESCAPE character ('=') in the Search/Database/Pgsql.php backend …

Aug 19, 2026
CVE-2026-76211
4.3 MEDIUM

phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT permission on admin API read endpoints for LDAP, Elasticsearch, OpenSearch, and dashboard configuration, allowing any authenticated user …

Aug 19, 2026
CVE-2026-76210
6.5 MEDIUM

phpMyFAQ before 4.1.6 does not adequately sanitize HTML in FAQ answers before generating PDFs via TCPDF. An attacker with permission to create or edit FAQ …

Aug 19, 2026
CVE-2026-76209
4.3 MEDIUM

phpMyFAQ versions before v4.1.6 fail to validate the security.enableRegistration setting in API endpoints, allowing attackers to create user accounts when registration is disabled. Attackers can …

Aug 19, 2026
CVE-2026-76206
5.3 MEDIUM

phpMyFAQ versions before 4.1.7 fail to validate active status in the PDF export endpoint, allowing unauthenticated attackers to retrieve draft FAQ metadata. Attackers can access …

Aug 19, 2026
CVE-2026-75920
5.3 MEDIUM

phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing sensitive files including database credentials. Unauthenticated attackers can race …

Aug 19, 2026
CVE-2026-75919
5.3 MEDIUM

phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability in SetupController that allows unauthenticated attackers to run database migrations and create configuration backups when maintenance mode …

Aug 19, 2026
CVE-2026-75148
6.1 MEDIUM

cgltf through 1.15 contains an integer overflow vulnerability in the non-sparse accessor bounds check within cgltf_validate() that allows remote attackers to cause memory disclosure and …

Aug 19, 2026
CVE-2026-70424
6.5 MEDIUM

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker …

Aug 19, 2026
CVE-2026-70423
6.5 MEDIUM

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could …

Aug 19, 2026
CVE-2026-50720
6.4 MEDIUM

The Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of the RSA signature output against a single 32-bit word …

Aug 19, 2026
CVE-2026-50719
6.8 MEDIUM

The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table from the SPL header before …

Aug 19, 2026
CVE-2026-73363
6.5 MEDIUM

Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions.

Aug 19, 2026
CVE-2026-76166
4.3 MEDIUM

A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single crafted UDP multicast datagram with a valid HTTP status line and a "Server:" …

Aug 19, 2026
CVE-2026-75900
6.1 MEDIUM

An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the buffer length against sizeof(bh), where bh is a pointer, instead …

Aug 19, 2026
CVE-2026-15446
6.4 MEDIUM

The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content in all versions up …

Aug 19, 2026
CVE-2026-18980
6.3 MEDIUM

A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the file src/tools/builtin/shell.rs. Such manipulation leads to command injection. …

Aug 6, 2026
CVE-2026-18976
6.3 MEDIUM

A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions of the file agent/agent_init.py of the component disabled_toolsets Handler. This …

Aug 6, 2026
CVE-2026-18974
5.3 MEDIUM

A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the file server.py of the component execute_tool_manually Endpoint. The …

Aug 6, 2026
CVE-2026-18968
4.3 MEDIUM

A security vulnerability has been detected in ttttonyhe OBlog up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f. This issue affects some unknown processing of the file /tags.php. Such manipulation of …

Aug 6, 2026
CVE-2026-71318
4.8 MEDIUM

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply a top-level `as` prop to the …

Aug 5, 2026
CVE-2026-71313
6.9 MEDIUM

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in …

Aug 5, 2026
CVE-2026-71311
6.4 MEDIUM

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, a valid but nondefault FTP …

Aug 5, 2026
CVE-2026-71310
5.9 MEDIUM

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, the shared HTTP CONNECT helper …

Aug 5, 2026
CVE-2026-18959
5.4 MEDIUM

A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::destroyFiles of the file innopacks/restapi/routes/panel-api.php of the …

Aug 5, 2026
CVE-2026-70618
4.3 MEDIUM

Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user to enumerate complete guild membership by querying the GET /guilds/{guild_id}/roles/{role_id}/member-ids …

Aug 5, 2026
CVE-2026-70616
6.5 MEDIUM

boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanently exhaust server file descriptors, goroutines, and memory by sending requests …

Aug 5, 2026
CVE-2026-21766
5.4 MEDIUM

The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Under certain very specific use cases and specific configurations, sensitive …

Aug 5, 2026
CVE-2026-18954
5.5 MEDIUM

Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate …

Aug 5, 2026
CVE-2026-7869
5.4 MEDIUM

IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bases`). This occurs because user-supplied knowledge base names …

Aug 5, 2026
CVE-2026-7658
6.5 MEDIUM

IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This …

Aug 5, 2026
CVE-2026-70612
5.4 MEDIUM

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, requests to open external …

Aug 5, 2026
CVE-2026-63457
6.5 MEDIUM

A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.

Aug 5, 2026
CVE-2026-10547
5.9 MEDIUM

IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated user to inject arbitrary graph …

Aug 5, 2026
CVE-2026-7657
6.5 MEDIUM

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enforcement.

Aug 5, 2026
CVE-2026-70611
6.9 MEDIUM

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3, the DevTools reveal in …

Aug 5, 2026
CVE-2026-70610
5.4 MEDIUM

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across the …

Aug 5, 2026
CVE-2026-70609
5.7 MEDIUM

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, the mode option of …

Aug 5, 2026
CVE-2026-70447
4.3 MEDIUM

Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

Aug 5, 2026
CVE-2026-70446
4.3 MEDIUM

Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

Aug 5, 2026
CVE-2026-70444
4.3 MEDIUM

A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials …

Aug 5, 2026
CVE-2026-70443
4.3 MEDIUM

Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to have Jenkins send credentials …

Aug 5, 2026
CVE-2026-70442
4.3 MEDIUM

Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and …

Aug 5, 2026
CVE-2026-70441
5.4 MEDIUM

Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pages, resulting in a stored …

Aug 5, 2026
CVE-2026-70440
5.4 MEDIUM

Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a JavaScript context, resulting in a stored cross-site scripting …

Aug 5, 2026
CVE-2026-70439
6.5 MEDIUM

Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appropriate permissions to invoke the conversion functionality.

Aug 5, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.