CVE Database

52018+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-63729
6.6 MEDIUM

The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers …

Jul 21, 2026
CVE-2026-16334
6.3 MEDIUM

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code of the file /prescriptionorder.php. Such manipulation of the argument editid …

Jul 21, 2026
CVE-2026-63728
6.3 MEDIUM

Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and …

Jul 21, 2026
CVE-2026-64626
6.4 MEDIUM

AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback …

Jul 20, 2026
CVE-2026-57852
5.6 MEDIUM

Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured scheduled jobs by exploiting a short-circuit logic flaw …

Jul 20, 2026
CVE-2026-51385
6.9 MEDIUM

An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url, safe_fetch, _build_opener, _fetch_html and _download_binary …

Jul 20, 2026
CVE-2026-51025
6.1 MEDIUM

Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary code via the ClientMessageController.java file

Jul 20, 2026
CVE-2026-47144
5.5 MEDIUM

Shamefile is a linter for undocumented linter warnings. Prior to version 0.1.7, a path traversal vulnerability in `shame next` allows an attacker-controlled `shamefile.yaml` to disclose …

Jul 20, 2026
CVE-2026-47128
6.1 MEDIUM

nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landlock/seccomp policies allow access to …

Jul 20, 2026
CVE-2026-44510
6.5 MEDIUM

Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, the receiver-side out-of-bounds array …

Jul 20, 2026
CVE-2026-12900
6.4 MEDIUM

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/image` block in …

Jul 20, 2026
CVE-2026-58624
5.4 MEDIUM

Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.apache.sshd:sshd-git provides though …

Jul 20, 2026
CVE-2026-55219
5.3 MEDIUM

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the credit payment implementation in app/Livewire/Invoices/Show.php executes …

Jul 20, 2026
CVE-2026-53596
5.3 MEDIUM

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeScout helpdesk application does not enforce …

Jul 20, 2026
CVE-2026-53594
4.9 MEDIUM

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. FreeScout's `Manage -> Logs -> App Logs` feature uses the bundled …

Jul 20, 2026
CVE-2026-44585
5.4 MEDIUM

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the ticket creation endpoint accepts a user-supplied …

Jul 20, 2026
CVE-2026-44584
4.3 MEDIUM

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the email update functionality fails to invalidate …

Jul 20, 2026
CVE-2026-44583
5.3 MEDIUM

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the PayPal webhook endpoint /extensions/paypal/webhook processes the …

Jul 20, 2026
CVE-2026-44509
6.3 MEDIUM

Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, previous bug fixes for …

Jul 20, 2026
CVE-2026-44507
4.8 MEDIUM

Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, when using a daemon …

Jul 20, 2026
CVE-2026-53592
4.6 MEDIUM

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in the `getQueryParam` function `/public/js/main.js` and was …

Jul 20, 2026
CVE-2026-44230
6.1 MEDIUM

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not …

Jul 20, 2026
CVE-2026-44229
5.4 MEDIUM

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a …

Jul 20, 2026
CVE-2026-63768
4.3 MEDIUM

cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows attackers to redirect users to arbitrary URLs by crafting …

Jul 20, 2026
CVE-2026-63730
5.0 MEDIUM

HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to make requests to arbitrary internal network …

Jul 20, 2026
CVE-2026-61901
6.1 MEDIUM

The Joomla extension Hikashop is vulnerable to an open redirect.

Jul 20, 2026
CVE-2026-55639
5.3 MEDIUM

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Security Data within the Client MCS …

Jul 20, 2026
CVE-2026-45295
6.5 MEDIUM

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tracking endpoint `GET /thread/read/{conversation_id}/{thread_id}` allows …

Jul 20, 2026
CVE-2026-44228
5.4 MEDIUM

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Scripting (XSS) vulnerability, …

Jul 20, 2026
CVE-2026-44227
6.1 MEDIUM

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. …

Jul 20, 2026
CVE-2026-26483
6.1 MEDIUM

Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management functionality. The application fails to properly sanitize user-supplied input …

Jul 20, 2026
CVE-2026-58482
5.9 MEDIUM

Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalInbox` (`lib/approval-inbox.ts`). It is the network surface of the human-in-the-loop Approval Gate, which …

Jul 20, 2026
CVE-2026-58481
6.5 MEDIUM

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped file access under a configured sandbox `basePath`, but its path containment checks …

Jul 20, 2026
CVE-2026-58414
5.5 MEDIUM

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using `_collectBackupFiles()`. `_collectBackupFiles()` uses `statSync(full)`, which follows symlinks. If `data/<env>` contains …

Jul 20, 2026
CVE-2026-58413
6.1 MEDIUM

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, backupId)` computes the backup path with `join(envDir, '.backups', backupId)` and only checks that this …

Jul 20, 2026
CVE-2026-55645
6.5 MEDIUM

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of Client Control PDUs. During the RDP connection …

Jul 20, 2026
CVE-2026-55238
5.3 MEDIUM

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Confirm Active PDU, where during the …

Jul 20, 2026
CVE-2026-50743
5.4 MEDIUM

A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted …

Jul 20, 2026
CVE-2026-47276
6.5 MEDIUM

In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `properties_parse()` allows an authenticated attacker to crash the NanoMQ broker by sending a POST …

Jul 20, 2026
CVE-2026-44978
5.3 MEDIUM

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap out-of-bounds read vulnerability within the FIPS-specific receive paths. This vulnerability does …

Jul 20, 2026
CVE-2026-42218
5.3 MEDIUM

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login interface. Due to a discrepancy in …

Jul 20, 2026
CVE-2026-35217
6.5 MEDIUM

NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` handling: if a subscription entry is missing the final 1-byte `Subscription Options` field, the broker …

Jul 20, 2026
CVE-2026-32823
4.3 MEDIUM

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, …

Jul 20, 2026
CVE-2026-32819
4.3 MEDIUM

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, …

Jul 20, 2026
CVE-2026-6793
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT Poll allows Stored XSS. This issue affects …

Jul 20, 2026
CVE-2026-63428
5.8 MEDIUM

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id, name, value}]` array from the submitter and stores it verbatim …

Jul 20, 2026
CVE-2026-63102
5.4 MEDIUM

rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role …

Jul 20, 2026
CVE-2026-51026
6.5 MEDIUM

Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a crafted request.

Jul 20, 2026
CVE-2026-48824
5.3 MEDIUM

Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2026-45710, "Mailpit: Set a default 50MB p/m …

Jul 20, 2026
CVE-2026-46671
4.4 MEDIUM

Rust OneNote File Parser is a parser for Microsoft OneNote files implemented in Rust. Prior to version 1.1.1, a maliciously crafted `.onetoc2` table-of-contents file can …

Jul 20, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.