CVE Database

138188+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-6598
4.3 MEDIUM

A security vulnerability has been detected in langflow-ai langflow up to 1.8.3. The affected element is the function create_project/encrypt_auth_settings of the file src/backend/base/Langflow/api/v1/projects.py of the …

Apr 20, 2026
CVE-2026-32965
7.5 HIGH

Initialization of a resource with an insecure default vulnerability exists in SD-330AC and AMC Manager provided by silex technology, Inc. When the affected device is …

Apr 20, 2026
CVE-2026-32964
6.5 MEDIUM

SD-330AC and AMC Manager provided by silex technology, Inc. contain an improper neutralization of CRLF sequences ('CRLF Injection') vulnerability. Processing some crafted configuration data may …

Apr 20, 2026
CVE-2026-32963
6.1 MEDIUM

SD-330AC and AMC Manager provided by silex technology, Inc. contain a reflected cross-site scripting vulnerability. When a user logs in to the affected device and …

Apr 20, 2026
CVE-2026-32962
5.3 MEDIUM

SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue. The device configuration may be altered without authentication.

Apr 20, 2026
CVE-2026-32961
5.3 MEDIUM

SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in packet data processing of sx_smpd. Processing a crafted packet …

Apr 20, 2026
CVE-2026-32960
6.5 MEDIUM

SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a sensitive information in resource not removed before reuse. An attacker may …

Apr 20, 2026
CVE-2026-32959
5.9 MEDIUM

SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a use of a broken or risky cryptographic algorithm. Information in the …

Apr 20, 2026
CVE-2026-32958
6.5 MEDIUM

SD-330AC and AMC Manager provided by silex technology, Inc. use a hard-coded cryptographic key. An administrative user may be directed to apply a fake firmware …

Apr 20, 2026
CVE-2026-32957
5.3 MEDIUM

SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue on firmware maintenance. Arbitrary file may be uploaded …

Apr 20, 2026
CVE-2026-32956
9.8 CRITICAL

SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed …

Apr 20, 2026
CVE-2026-32955
8.8 HIGH

SD-330AC and AMC Manager provided by silex technology, Inc. contain a stack-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed …

Apr 20, 2026
CVE-2026-6597
2.7 LOW

A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_terms of the file src/backend/base/langflow/api/utils/core.py of the component Flow Using …

Apr 20, 2026
CVE-2026-6596
7.3 HIGH

A security flaw has been discovered in langflow-ai langflow up to 1.1.0. This issue affects the function create_upload_file of the file src/backend/base/Langflow/api/v1/endpoints.py of the component …

Apr 20, 2026
CVE-2026-6595
7.3 HIGH

A vulnerability was identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This vulnerability affects unknown code of the file buslocation.php of the component HTTP …

Apr 20, 2026
CVE-2026-6594
7.3 HIGH

A vulnerability was determined in brikcss merge up to 1.3.0. This affects an unknown part. Executing a manipulation of the argument __proto__/constructor.prototype/prototype can lead to …

Apr 20, 2026
CVE-2026-6593
3.5 LOW

A vulnerability was found in ComfyUI up to 0.13.0. Affected by this issue is some unknown functionality of the file server.py of the component View …

Apr 20, 2026
CVE-2026-6592
3.5 LOW

A vulnerability has been found in ComfyUI up to 0.13.0. Affected by this vulnerability is the function getuserdata of the file app/user_manager.py of the component …

Apr 20, 2026
CVE-2026-6591
4.3 MEDIUM

A flaw has been found in ComfyUI up to 0.13.0. Affected is the function folder_paths.get_annotated_filepath of the file folder_paths.py of the component LoadImage Node. This …

Apr 20, 2026
CVE-2026-6590
4.3 MEDIUM

A vulnerability was detected in ComfyUI up to 0.13.0. This impacts the function get_model_preview of the file app/model_manager.py of the component Model Preview Endpoint. The …

Apr 20, 2026
CVE-2026-6589
4.3 MEDIUM

A security vulnerability has been detected in ComfyUI up to 0.13.0. This affects the function create_origin_only_middleware of the file server.py. The manipulation leads to cross-site …

Apr 20, 2026
CVE-2026-6588
6.5 MEDIUM

A weakness has been identified in serge-chat serge up to 1.4TB. The impacted element is the function download_model/delete_model of the file api/src/serge/routers/model.py of the component …

Apr 20, 2026
CVE-2026-6587
6.3 MEDIUM

A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3. The affected element is the function _try_process_local_file/_try_process_url of the file src/ragas/metrics/collections/multi_modal_faithfulness/util.py of the …

Apr 20, 2026
CVE-2026-6586
6.3 MEDIUM

A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Impacted is the function get_budget/update_budget of the file superagi/controllers/budget.py of the component Budget Endpoint. Such …

Apr 20, 2026
CVE-2026-6585
5.4 MEDIUM

A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This issue affects the function update_organisation of the file superagi/controllers/organisation.py of the component Organisation Update …

Apr 20, 2026
CVE-2026-6584
5.4 MEDIUM

A vulnerability was found in TransformerOptimus SuperAGI up to 0.0.14. This vulnerability affects the function update_user of the file superagi/controllers/user.py of the component User Update …

Apr 20, 2026
CVE-2026-6583
5.4 MEDIUM

A vulnerability has been found in TransformerOptimus SuperAGI up to 0.0.14. This affects the function delete_api_key/edit_api_key of the file superagi/controllers/api_key.py of the component API Key …

Apr 19, 2026
CVE-2026-6582
7.3 HIGH

A flaw has been found in TransformerOptimus SuperAGI up to 0.0.14. Affected by this issue is the function get_vector_db_details of the file superagi/controllers/vector_dbs.py of the …

Apr 19, 2026
CVE-2026-6581
8.8 HIGH

A vulnerability was detected in H3C Magic B1 up to 100R004. Affected by this vulnerability is the function SetMobileAPInfoById of the file /goform/aspForm. Performing a …

Apr 19, 2026
CVE-2026-6580
7.3 HIGH

A security vulnerability has been detected in liangliangyy DjangoBlog up to 2.1.0.0. Affected is an unknown function of the file owntracks/views.py of the component Amap …

Apr 19, 2026
CVE-2026-6579
6.5 MEDIUM

A weakness has been identified in liangliangyy DjangoBlog up to 2.1.0.0. This impacts an unknown function of the file blog/views.py of the component Clean Endpoint. …

Apr 19, 2026
CVE-2026-6578
5.6 MEDIUM

A security flaw has been discovered in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the component Setting …

Apr 19, 2026
CVE-2026-6577
7.3 HIGH

A vulnerability was identified in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file owntracks/views.py of the component logtracks …

Apr 19, 2026
CVE-2026-6576
6.3 MEDIUM

A vulnerability was determined in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function CommandHandler of the file servermanager/api/commonapi.py of the component WeChat …

Apr 19, 2026
CVE-2026-6574
7.3 HIGH

A vulnerability has been found in osuuu LightPicture up to 1.2.2. This issue affects some unknown processing of the file /public/install/lp.sql of the component API …

Apr 19, 2026
CVE-2026-6573
6.3 MEDIUM

A vulnerability was detected in PHPEMS 11.0. This affects the function temppage of the file /app/exam/controller/exams.master.php of the component Instant Exam Creation Handler. The manipulation …

Apr 19, 2026
CVE-2026-6572
5.6 MEDIUM

A security vulnerability has been detected in Collabora KodExplorer up to 4.52. Affected by this issue is some unknown functionality of the file /app/controller/share.class.php of …

Apr 19, 2026
CVE-2026-6571
6.3 MEDIUM

A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/controller/systemRole.class.php. Executing a …

Apr 19, 2026
CVE-2026-6570
2.7 LOW

A security flaw has been discovered in kodcloud KodExplorer up to 4.52. Affected is the function initInstall of the file /app/controller/systemMember.class.php. Performing a manipulation of …

Apr 19, 2026
CVE-2026-6569
7.3 HIGH

A vulnerability was identified in kodcloud KodExplorer up to 4.52. This impacts the function fileGet of the file /app/controller/share.class.php of the component fileGet Endpoint. Such …

Apr 19, 2026
CVE-2026-6568
7.3 HIGH

A vulnerability was determined in kodcloud KodExplorer up to 4.52. This affects the function share.class.php::initShareOld of the file /app/controller/share.class.php of the component Public Share Handler. …

Apr 19, 2026
CVE-2026-6564
4.3 MEDIUM

A vulnerability was found in EMQ EMQX Enterprise up to 6.1.0. The impacted element is an unknown function of the component Session Handling. The manipulation …

Apr 19, 2026
CVE-2026-6563
8.8 HIGH

A vulnerability has been found in H3C Magic B1 up to 100R004. The affected element is the function SetAPWifiorLedInfoById of the file /goform/aspForm. The manipulation …

Apr 19, 2026
CVE-2026-6562
7.3 HIGH

A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is the function getListByPage of the file /index/Search/index.html. Executing a manipulation of the argument keyword …

Apr 19, 2026
CVE-2026-6561
4.7 MEDIUM

A vulnerability was detected in EyouCMS up to 1.7.1. This issue affects the function edit_adminlogo of the file application/admin/controller/Index.php. Performing a manipulation of the argument …

Apr 19, 2026
CVE-2026-6560
8.8 HIGH

A security vulnerability has been detected in H3C Magic B0 up to 100R002. This vulnerability affects the function Edit_BasicSSID of the file /goform/aspForm. Such manipulation …

Apr 19, 2026
CVE-2026-6559
4.3 MEDIUM

A weakness has been identified in Wavlink WL-WN579A3 220323. This affects the function sub_401F80 of the file /cgi-bin/login.cgi. This manipulation of the argument Hostname causes …

Apr 19, 2026
CVE-2026-0868
6.4 MEDIUM

The EMC – Easily Embed Calendly Scheduling Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's calendly shortcode in all versions …

Apr 19, 2026
CVE-2026-6056

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Apr 18, 2026
CVE-2026-41242
9.8 CRITICAL

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of …

Apr 18, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.