CVE Database

9856+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-30618
9.8 CRITICAL

xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker can access the …

Jul 15, 2026
CVE-2026-26718
9.1 CRITICAL

A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell …

Jul 15, 2026
CVE-2025-65720
9.8 CRITICAL

An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML …

Jul 15, 2026
CVE-2026-54052
9.9 CRITICAL

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy …

Jul 15, 2026
CVE-2026-52887
10.0 CRITICAL

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value …

Jul 15, 2026
CVE-2026-51380
9.8 CRITICAL

Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or potentially execute remote code via …

Jul 15, 2026
CVE-2026-49352
9.8 CRITICAL

9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in src/app/api/auth/login/route.js, src/middleware.js, and later …

Jul 15, 2026
CVE-2026-46339
10.0 CRITICAL

9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated registration of …

Jul 15, 2026
CVE-2026-49445
9.2 CRITICAL

Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envoy …

Jul 15, 2026
CVE-2026-62948
9.6 CRITICAL

OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefiles.c …

Jul 15, 2026
CVE-2026-53513
9.6 CRITICAL

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST /sso/update-provider endpoints accept attacker-controlled oidcConfig.userInfoEndpoint, …

Jul 15, 2026
CVE-2026-53512
9.1 CRITICAL

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token …

Jul 15, 2026
CVE-2026-14960
9.8 CRITICAL

Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including `TDE_IOCTL_INDEXIO_READ` and `TDE_IOCTL_INDEXIO_WRITE` permit unprivileged user-mode callers to perform …

Jul 15, 2026
CVE-2026-62378
9.0 CRITICAL

RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS Console components/object/preview-modal.tsx and components/object/pdf-viewer.tsx extension-based PDF …

Jul 15, 2026
CVE-2026-52843
9.3 CRITICAL

Lightpanda is a headless browser designed for AI and automation. Prior to 0.2.9, Lightpanda fetch() and XMLHttpRequest unconditionally attached session cookies to every HTTP request, …

Jul 15, 2026
CVE-2026-52842
9.3 CRITICAL

Lightpanda is a headless browser designed for AI and automation. Prior to 0.3.1, Lightpanda searched for @ across the entire URL string instead of only …

Jul 15, 2026
CVE-2026-50148
10.0 CRITICAL

Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with …

Jul 15, 2026
CVE-2026-44986
9.9 CRITICAL

Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing profile …

Jul 15, 2026
CVE-2026-61736
9.3 CRITICAL

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* combined with allow_credentials=True in lightrag/api/lightrag_server.py, causing Starlette CORSMiddleware to effectively …

Jul 15, 2026
CVE-2026-43637
9.1 CRITICAL

Cornac before 2.6.0 contains a path traversal (Tar Slip) vulnerability that allows attackers to write arbitrary files outside the intended cache directory by supplying a …

Jul 15, 2026
CVE-2026-61451
9.6 CRITICAL

The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoint. The sanitizeHttpUrl() function …

Jul 15, 2026
CVE-2026-56699
10.0 CRITICAL

Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. Attackers can …

Jul 15, 2026
CVE-2026-5270
9.8 CRITICAL

An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue …

Jul 14, 2026
CVE-2026-5269
9.8 CRITICAL

In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these …

Jul 14, 2026
CVE-2026-51808
9.8 CRITICAL

Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the openhtj2k_decoder_impl::invoke, invoke_line_based, invoke_line_based_stream, and invoke_line_based_predecoded function in source/core/interface/decoder.cpp

Jul 14, 2026
CVE-2026-51807
9.8 CRITICAL

Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (fixed in v0.18.4) caused by missing bounds validation before coding-pass lengths are written to …

Jul 14, 2026
CVE-2026-48807
9.1 CRITICAL

Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace …

Jul 14, 2026
CVE-2026-48806
9.1 CRITICAL

Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to …

Jul 14, 2026
CVE-2026-48805
9.1 CRITICAL

Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), …

Jul 14, 2026
CVE-2026-48334
9.3 CRITICAL

Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Jul 14, 2026
CVE-2026-46634
9.8 CRITICAL

Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside …

Jul 14, 2026
CVE-2026-46633
9.8 CRITICAL

Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} …

Jul 14, 2026
CVE-2026-45363
9.1 CRITICAL

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts …

Jul 14, 2026
CVE-2026-38450
9.8 CRITICAL

An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of the …

Jul 14, 2026
CVE-2026-53486
9.1 CRITICAL

The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting …

Jul 14, 2026
CVE-2026-52101
9.1 CRITICAL

An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadRemote function in upload.go

Jul 14, 2026
CVE-2026-48327
9.0 CRITICAL

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this …

Jul 14, 2026
CVE-2026-48325
9.3 CRITICAL

ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. …

Jul 14, 2026
CVE-2026-48324
9.1 CRITICAL

ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution …

Jul 14, 2026
CVE-2026-48322
9.6 CRITICAL

ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of …

Jul 14, 2026
CVE-2026-48321
9.3 CRITICAL

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and …

Jul 14, 2026
CVE-2026-48319
9.1 CRITICAL

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in …

Jul 14, 2026
CVE-2026-48318
9.9 CRITICAL

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. …

Jul 14, 2026
CVE-2026-48284
9.6 CRITICAL

ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Jul 14, 2026
CVE-2026-15773
9.6 CRITICAL

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a …

Jul 14, 2026
CVE-2026-53633
9.8 CRITICAL

Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw …

Jul 14, 2026
CVE-2026-48359
9.6 CRITICAL

Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the …

Jul 14, 2026
CVE-2026-48358
9.1 CRITICAL

Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the …

Jul 14, 2026
CVE-2026-48356
9.6 CRITICAL

Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of …

Jul 14, 2026
CVE-2026-48259
9.6 CRITICAL

Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current …

Jul 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.