CVE Database

45217+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-77567
8.1 HIGH

Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication …

Aug 24, 2026
CVE-2026-75464
8.1 HIGH

OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().

Aug 24, 2026
CVE-2026-56135
7.4 HIGH

In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs-3g/security.c that allows an attacker to corrupt heap memory in the …

Aug 24, 2026
CVE-2026-52492
7.8 HIGH

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based …

Aug 24, 2026
CVE-2026-19568
7.8 HIGH

A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to …

Aug 24, 2026
CVE-2026-16783
7.8 HIGH

A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to …

Aug 24, 2026
CVE-2026-76098
7.5 HIGH

Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates …

Aug 24, 2026
CVE-2026-75369
7.1 HIGH

An out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via …

Aug 24, 2026
CVE-2026-75368
7.5 HIGH

A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying …

Aug 24, 2026
CVE-2026-61419
7.8 HIGH

Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, …

Aug 24, 2026
CVE-2026-75371
7.5 HIGH

An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-proximate attackers with UART access to cause a Denial …

Aug 24, 2026
CVE-2026-71506
8.1 HIGH

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete …

Aug 24, 2026
CVE-2026-71505
7.1 HIGH

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation …

Aug 24, 2026
CVE-2026-71504
8.1 HIGH

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of …

Aug 24, 2026
CVE-2026-40877
8.7 HIGH

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which …

Aug 24, 2026
CVE-2026-30864
8.9 HIGH

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. …

Aug 24, 2026
CVE-2025-26238
8.1 HIGH

In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code.

Aug 24, 2026
CVE-2025-26237
8.1 HIGH

D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can be exploited to run arbitrary commands.

Aug 24, 2026
CVE-2026-76838
8.5 HIGH

Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule.php resolves the hostname with gethostbyname() and rejects …

Aug 24, 2026
CVE-2026-76836
8.8 HIGH

AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in backend/src/Entity/Station.php is annotated …

Aug 24, 2026
CVE-2026-76073
8.8 HIGH

Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset …

Aug 24, 2026
CVE-2026-76072
7.4 HIGH

The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands when running unattended. In headless mode and auto mode the …

Aug 24, 2026
CVE-2026-71943
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerability is caused by insufficient filtering of the username and password …

Aug 24, 2026
CVE-2026-71942
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a …

Aug 24, 2026
CVE-2026-71941
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a …

Aug 24, 2026
CVE-2026-71940
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE function. The vulnerability is caused by copying the name field into …

Aug 24, 2026
CVE-2026-71939
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. The vulnerability is caused by copying the name field into …

Aug 24, 2026
CVE-2026-71938
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnerability is caused by unsafe copying of the portList field into …

Aug 24, 2026
CVE-2026-71937
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. The vulnerability is caused by repeated concatenation of the start_date, start_time, duration_time, …

Aug 24, 2026
CVE-2026-71936
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability is caused by unsafe concatenation of split valueN data into …

Aug 24, 2026
CVE-2026-71935
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnerability is caused by repeated string concatenation of the pathN, valueN, …

Aug 24, 2026
CVE-2026-71934
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability is caused by missing length checks when the host, count, …

Aug 24, 2026
CVE-2026-71931
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerability is caused by insufficient filtering before the filename field is …

Aug 24, 2026
CVE-2026-71930
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability is caused by insufficient filtering of the username and password …

Aug 24, 2026
CVE-2026-71929
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerability is caused by insufficient filtering of the username and password …

Aug 24, 2026
CVE-2026-71928
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerability is caused by insufficient filtering of the username and password …

Aug 24, 2026
CVE-2026-71927
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. The vulnerability is caused by insufficient filtering of the username and password …

Aug 24, 2026
CVE-2026-71926
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerability is caused by insufficient sanitization of the username, password, and …

Aug 24, 2026
CVE-2026-71925
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerability is caused by insufficient filtering of the username and password …

Aug 24, 2026
CVE-2026-71924
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability is caused by insufficient filtering of the username and password …

Aug 24, 2026
CVE-2026-71923
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerability is caused by insufficient filtering of the username and password …

Aug 24, 2026
CVE-2026-71922
7.5 HIGH

Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass …

Aug 24, 2026
CVE-2026-71919
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerability is caused by insufficient filtering of the config, act, pathN, …

Aug 24, 2026
CVE-2026-71918
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. The vulnerability is caused by insufficient filtering of the option, key, pw_encode, …

Aug 24, 2026
CVE-2026-71917
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerability is caused by insufficient validation of the host field before …

Aug 24, 2026
CVE-2026-71916
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. The vulnerability is caused by incomplete filtering of dangerous characters such as …

Aug 24, 2026
CVE-2026-71915
7.2 HIGH

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerability is caused by insufficient filtering of the usescript, usefile, and …

Aug 24, 2026
CVE-2026-71913
7.2 HIGH

Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vulnerability is caused by insufficient filtering before the restorekey field is …

Aug 24, 2026
CVE-2026-71912
7.2 HIGH

Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is caused by missing length checks during memory copy operations …

Aug 24, 2026
CVE-2026-71911
7.2 HIGH

Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The vulnerability is caused by missing length checks during memory copy operations …

Aug 24, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.