CVE Database

11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-89094
9.9 CRITICAL

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

Sep 10, 2026
CVE-2026-85025
9.8 CRITICAL

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared …

Sep 10, 2026
CVE-2026-75940
9.1 CRITICAL

A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.

Sep 10, 2026
CVE-2026-89086
9.1 CRITICAL

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to …

Sep 10, 2026
CVE-2026-89049
9.9 CRITICAL

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems …

Sep 10, 2026
CVE-2026-89042
9.1 CRITICAL

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can …

Sep 10, 2026
CVE-2026-68006
9.1 CRITICAL

An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/puma_http11/http11_parser.rl file

Sep 10, 2026
CVE-2026-88044
9.1 CRITICAL

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface …

Sep 10, 2026
CVE-2026-85228
9.1 CRITICAL

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a …

Sep 10, 2026
CVE-2026-68488
9.9 CRITICAL

A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.

Sep 10, 2026
CVE-2026-68487
9.9 CRITICAL

Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

Sep 10, 2026
CVE-2026-52098
9.8 CRITICAL

An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint

Sep 10, 2026
CVE-2026-88899
9.8 CRITICAL

knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to …

Sep 10, 2026
CVE-2026-88018
9.8 CRITICAL

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with …

Sep 10, 2026
CVE-2026-81468
9.1 CRITICAL

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A …

Sep 10, 2026
CVE-2026-81467
9.8 CRITICAL

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An …

Sep 10, 2026
CVE-2026-81048
9.6 CRITICAL

Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with …

Sep 10, 2026
CVE-2026-81046
9.4 CRITICAL

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading …

Sep 10, 2026
CVE-2026-88008
9.1 CRITICAL

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, …

Sep 10, 2026
CVE-2026-88007
9.1 CRITICAL

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, …

Sep 10, 2026
CVE-2026-81800
9.3 CRITICAL

Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.

Sep 10, 2026
CVE-2026-88877
9.8 CRITICAL

Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx provider mishandles Ingresses that carry both …

Sep 10, 2026
CVE-2026-88869
9.3 CRITICAL

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. …

Sep 10, 2026
CVE-2026-88864
9.1 CRITICAL

Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key …

Sep 10, 2026
CVE-2026-38626
9.8 CRITICAL

Garlic-Hub v1.0.1 is vulnerable to SQL Injection in src/Modules/Items/Repositories/ItemsRepository.php.

Sep 10, 2026
CVE-2026-9163
9.8 CRITICAL

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection. This issue …

Sep 10, 2026
CVE-2026-8323
9.3 CRITICAL

URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data. This issue …

Sep 10, 2026
CVE-2026-88285
9.4 CRITICAL

GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands.

Sep 10, 2026
CVE-2026-88278
9.8 CRITICAL

GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.

Sep 10, 2026
CVE-2026-59679
9.0 CRITICAL

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a …

Sep 10, 2026
CVE-2026-44950
9.0 CRITICAL

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) …

Sep 10, 2026
CVE-2026-80352
9.8 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerability in custom resource configuration allows an authorized CR …

Sep 10, 2026
CVE-2026-80351
9.8 CRITICAL

Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration …

Sep 10, 2026
CVE-2026-7188
9.8 CRITICAL

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows SQL Injection. …

Sep 10, 2026
CVE-2026-78361
9.1 CRITICAL

The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation checks on one of its front-end request handlers, and …

Sep 10, 2026
CVE-2026-77770
10.0 CRITICAL

The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names …

Sep 10, 2026
CVE-2026-84939
9.1 CRITICAL

Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup …

Sep 10, 2026
CVE-2026-67593
9.1 CRITICAL

A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and …

Sep 10, 2026
CVE-2026-57967
9.8 CRITICAL

An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. …

Sep 10, 2026
CVE-2026-49364
9.1 CRITICAL

An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 …

Sep 10, 2026
CVE-2026-19583
9.9 CRITICAL

Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it …

Sep 10, 2026
CVE-2026-18351
9.8 CRITICAL

The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, …

Sep 10, 2026
CVE-2026-87931
9.6 CRITICAL

A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple …

Sep 10, 2026
CVE-2026-71805
9.8 CRITICAL

An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0. Unauthenticated remote attackers can upload arbitrary files and write them outside the intended …

Sep 9, 2026
CVE-2026-71801
9.8 CRITICAL

An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core configuration file, which is …

Sep 9, 2026
CVE-2026-36433
9.8 CRITICAL

An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe …

Sep 9, 2026
CVE-2026-87911
9.6 CRITICAL

An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor …

Sep 9, 2026
CVE-2026-54694
9.6 CRITICAL

SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation …

Sep 9, 2026
CVE-2026-87929
9.8 CRITICAL

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator …

Sep 9, 2026
CVE-2026-67401
9.9 CRITICAL

A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component

Sep 9, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.