CVE Database

114379+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-58410
7.1 HIGH

ChurchCRM is an open-source church management system. Prior to version 7.4.0, there was an authorization flaw in the family-scoped endpoints which allowed low-privileged users to …

Jul 13, 2026
CVE-2026-58409
9.1 CRITICAL

ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve Remote Code Execution (RCE) on the server by installing …

Jul 13, 2026
CVE-2026-48364
8.2 HIGH

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context …

Jul 13, 2026
CVE-2026-48363
8.2 HIGH

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context …

Jul 13, 2026
CVE-2026-15595
4.3 MEDIUM

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /forsubject.php. This manipulation …

Jul 13, 2026
CVE-2026-15594
3.7 LOW

A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the library src/lib/media/hash.ts of the component Media Handler. The …

Jul 13, 2026
CVE-2026-58408
6.5 MEDIUM

ChurchCRM is an open-source church management system. Prior to version 7.4.0, a low-privileged user can bypass the /admin/export UI and exfiltrate the entire member directory. …

Jul 13, 2026
CVE-2026-58407

Rejected reason: Please submit CVE requests for each vulnerability.

Jul 13, 2026
CVE-2026-55773
8.8 HIGH

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 2.3.6, 3.4.1 and 4.9.0, …

Jul 13, 2026
CVE-2026-55771
8.8 HIGH

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 4.9.0, the EntityIdentifier.equals() has …

Jul 13, 2026
CVE-2026-12536
6.4 MEDIUM

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Module Title’ parameter in all versions up to, and including, …

Jul 13, 2026
CVE-2026-12385
4.3 MEDIUM

The Smart Slider 3 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1.37 via the 'keyword' parameter. …

Jul 13, 2026
CVE-2026-6875

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain …

Jul 13, 2026
CVE-2026-58228

Cross-site scripting vulnerability in phoenixframework phoenix_live_view allows an attacker to bypass URL scheme validation and execute JavaScript in a victim's browser session. The Phoenix.LiveView.Utils.valid_destination!/2 and …

Jul 13, 2026
CVE-2026-55772
8.8 HIGH

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 2.3.6, 3.4.1 and 4.9.0, …

Jul 13, 2026
CVE-2026-49972
8.8 HIGH

Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading a file with an embedded PHP …

Jul 13, 2026
CVE-2026-49971
6.1 MEDIUM

Laravel-Mediable before 7.0.0 contains a stored cross-site scripting vulnerability that allows authenticated or anonymous users to execute arbitrary JavaScript by uploading unsanitized SVG files containing …

Jul 13, 2026
CVE-2026-49970
8.8 HIGH

Laravel-Mediable before 7.0.0 contains a path traversal vulnerability in the File::sanitizePath() function that allows attackers to write uploaded files to arbitrary locations by controlling the …

Jul 13, 2026
CVE-2026-49969
7.4 HIGH

Laravel-Mediable before 7.0.0 contains a server-side request forgery vulnerability that allows remote attackers to issue arbitrary HTTP requests from the server by supplying unvalidated caller-controlled …

Jul 13, 2026
CVE-2026-26396
7.5 HIGH

OpenBMB XAgent v1.0.0 and before is vulnerable to path traversal in the file() function in XAgent/XAgentServer/application/routers/workspace.py. The input parameter “filename” is user-controllable and is concatenated …

Jul 13, 2026
CVE-2026-14906
5.3 MEDIUM

Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS application sandbox. This …

Jul 13, 2026
CVE-2025-45869
7.3 HIGH

LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can exploit the ShareFileCallback servlet by manipulating …

Jul 13, 2026
CVE-2026-61505
5.3 MEDIUM

Rejetto HFS 3.0.0 through 3.2.0 allows path traversal through the lang query parameter, permitting a remote unauthenticated attacker to read certain JSON files outside the …

Jul 13, 2026
CVE-2026-61504
5.4 MEDIUM

Rejetto HFS 3.0.0 through 3.2.0 does not escape file names in its fallback "basic" web listing, and this listing can be forced by any browser …

Jul 13, 2026
CVE-2026-61503
5.3 MEDIUM

Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the submitted username exists. A remote unauthenticated attacker can …

Jul 13, 2026
CVE-2026-61502
4.3 MEDIUM

Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its anti-CSRF header check. A remote attacker …

Jul 13, 2026
CVE-2026-61501
6.1 MEDIUM

Rejetto HFS 3.0.0 through 3.2.0 renders log entries in the administration panel as HTML without sanitization. A remote unauthenticated attacker can submit a failed login …

Jul 13, 2026
CVE-2026-61500
9.8 CRITICAL

Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients …

Jul 13, 2026
CVE-2026-61463
8.8 HIGH

Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without authorization checks. Attackers can …

Jul 13, 2026
CVE-2026-61462
8.6 HIGH

mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can …

Jul 13, 2026
CVE-2026-60103
6.1 MEDIUM

Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerability that allows attackers to trigger a crash or read adjacent heap memory by supplying a crafted …

Jul 13, 2026
CVE-2026-53365

In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix zerocopy completion for multi-skb sends When a large message is fragmented into multiple …

Jul 13, 2026
CVE-2026-53364

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate() hci_le_big_terminate() allocates iso_list_data via kzalloc_obj but returns 0 …

Jul 13, 2026
CVE-2026-57433
9.8 CRITICAL

Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from …

Jul 13, 2026
CVE-2026-57432
8.4 HIGH

Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size …

Jul 13, 2026
CVE-2026-13221
9.1 CRITICAL

Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie …

Jul 13, 2026
CVE-2026-59245
8.1 HIGH

In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so …

Jul 13, 2026
CVE-2026-58065
8.1 HIGH

The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path …

Jul 13, 2026
CVE-2026-6847

Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function. The application exposes an endpoint that allows unauthenticated …

Jul 13, 2026
CVE-2026-61498
9.8 CRITICAL

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying …

Jul 13, 2026
CVE-2026-60121
9.8 CRITICAL

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a …

Jul 13, 2026
CVE-2026-40553
7.5 HIGH

Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially …

Jul 13, 2026
CVE-2026-40469
9.1 CRITICAL

Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and …

Jul 13, 2026
CVE-2026-40468
9.1 CRITICAL

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and …

Jul 13, 2026
CVE-2026-40467
7.5 HIGH

Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk …

Jul 13, 2026
CVE-2026-15584
7.5 HIGH

A privilege escalation vulnerability was found in the incluster-checks tool for OpenShift. The tool creates privileged debug pods with host filesystem access in the shared …

Jul 13, 2026
CVE-2026-15559
6.3 MEDIUM

A vulnerability was detected in CodeAstro Simple Online Leave Management System 1.0. This affects an unknown part of the file /SimpleOnlineLeave/admin/accept.php of the component POST …

Jul 13, 2026
CVE-2026-62147
6.5 MEDIUM

The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated …

Jul 13, 2026
CVE-2026-15558
6.3 MEDIUM

A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file …

Jul 13, 2026
CVE-2026-12257

Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. The flaw is located in the endpoint “/index.cfm/_api/json/v1/default”, where the …

Jul 13, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.