CVE Database

52246+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-44640
4.5 MEDIUM

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->prov_data is stored as nni_quic_conn* during dialing, but read as ex_quic_conn* during …

May 29, 2026
CVE-2026-44287
6.3 MEDIUM

FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at projects/code-sandbox/src/pool/worker.ts:356 blocks dynamic import() with the regex /\bimport\s*\(/.test(code). JavaScript syntax …

May 29, 2026
CVE-2026-42500
5.3 MEDIUM

Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image.

May 29, 2026
CVE-2026-34127
4.8 MEDIUM

A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG108PE v5 switch due to improper sanitation of the …

May 29, 2026
CVE-2026-49386
6.5 MEDIUM

In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas

May 29, 2026
CVE-2026-49385
6.5 MEDIUM

In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts

May 29, 2026
CVE-2026-49384
6.1 MEDIUM

In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible

May 29, 2026
CVE-2026-49382
4.5 MEDIUM

In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin

May 29, 2026
CVE-2026-49379
6.5 MEDIUM

In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names

May 29, 2026
CVE-2026-49378
4.3 MEDIUM

In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion

May 29, 2026
CVE-2026-49377
4.3 MEDIUM

In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters

May 29, 2026
CVE-2026-49376
6.5 MEDIUM

In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin

May 29, 2026
CVE-2026-49375
6.1 MEDIUM

In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page

May 29, 2026
CVE-2026-49369
4.3 MEDIUM

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages

May 29, 2026
CVE-2026-47745
6.5 MEDIUM

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carriers exposed inline toggles and per-record actions (enable, …

May 29, 2026
CVE-2026-47742
6.5 MEDIUM

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping, Files) had no …

May 29, 2026
CVE-2026-47741
5.9 MEDIUM

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the Order row before checking and incrementing the discount's total_use counter. Under …

May 29, 2026
CVE-2026-46344
5.3 MEDIUM

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS …

May 29, 2026
CVE-2026-44611
5.4 MEDIUM

Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks.

May 29, 2026
CVE-2026-44518
5.3 MEDIUM

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS …

May 29, 2026
CVE-2026-42951
5.4 MEDIUM

An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes account data and password hashes.

May 29, 2026
CVE-2026-40425
5.7 MEDIUM

The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password.

May 29, 2026
CVE-2026-45660
5.4 MEDIUM

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image proxy's URL validation could be bypassed …

May 29, 2026
CVE-2026-45626
6.3 MEDIUM

Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /environments/{id}/volumes/{volumeName}/browse accepts a path query parameter that is …

May 29, 2026
CVE-2026-10070
4.7 MEDIUM

A vulnerability was found in macrozheng mall up to 1.0.3. This affects an unknown function of the file /admin/update/ of the component Super Admin Password …

May 29, 2026
CVE-2026-39229
6.5 MEDIUM

Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated attacker with low-level privileges can exploit this …

May 29, 2026
CVE-2026-36324
6.1 MEDIUM

SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of user supplied input in the user registration functionality …

May 29, 2026
CVE-2026-35673
6.5 MEDIUM

OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked tabs. Attackers with access …

May 29, 2026
CVE-2026-34507
5.4 MEDIUM

OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allowFrom policy checks. Attackers can …

May 29, 2026
CVE-2026-32906
4.3 MEDIUM

OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals that allows exec-authorized users to resolve plugin approvals through the exec approver gate. …

May 29, 2026
CVE-2026-10101
6.3 MEDIUM

ACM/MCE assisted-service writes raw referenced pull-secret contents into `InfraEnv.status.conditions[].message` when pull-secret validation fails. A namespace principal with the stock `view` ClusterRole cannot directly read Secrets, …

May 29, 2026
CVE-2026-10099
4.0 MEDIUM

XX-Net V5.16.6 contains a WebSocket frame parsing vulnerability in the WebSocket_receive_worker routine of simple_http_server.py that allows attackers to cause corrupted application data by sending unmasked …

May 29, 2026
CVE-2026-10064
6.3 MEDIUM

A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetPortTr of the file /goform/formSetPortTr. Performing a manipulation of the argument …

May 29, 2026
CVE-2018-25397
5.3 MEDIUM

PHP-SHOP 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to add administrative users by crafting malicious HTML forms. Attackers can trick authenticated …

May 29, 2026
CVE-2018-25393
6.5 MEDIUM

Navigate CMS 2.8.5 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by injecting directory traversal sequences in the id parameter. …

May 29, 2026
CVE-2018-25387
5.3 MEDIUM

HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords by submitting forged requests to the user update endpoint. …

May 29, 2026
CVE-2018-25384
5.4 MEDIUM

Wikidforum 2.20 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted HTML in the reply_text parameter. Attackers can …

May 29, 2026
CVE-2026-41159
5.3 MEDIUM

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, Mermaid's default configuration allows …

May 29, 2026
CVE-2026-41150
5.3 MEDIUM

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service …

May 29, 2026
CVE-2026-49325
4.6 MEDIUM

Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows a physical attacker with …

May 29, 2026
CVE-2026-49316
4.6 MEDIUM

Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the …

May 29, 2026
CVE-2026-47696
4.3 MEDIUM

WWBN AVideo is an open source video platform. In 29.0 and earlier, plugin/AuthorizeNet/processPayment.json.php credits the logged-in user's wallet based only on the attacker-controlled amount POST …

May 29, 2026
CVE-2026-47694
5.4 MEDIUM

WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input and later renders category_description as raw …

May 29, 2026
CVE-2026-46337
5.3 MEDIUM

WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacker can read arbitrary image files anywhere on disk that …

May 29, 2026
CVE-2026-45731
4.9 MEDIUM

WWBN AVideo is an open source video platform. In 29.0 and earlier, view/update.php reads $_POST['updateFile'] as a relative path under updatedb/ and passes it to …

May 29, 2026
CVE-2026-45620
5.3 MEDIUM

WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an entry guard: …

May 29, 2026
CVE-2026-45619
6.5 MEDIUM

WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and other locations do not use the $resolvedIP out-param of isSSRFSafeURL() …

May 29, 2026
CVE-2026-45610
5.7 MEDIUM

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/LoginControl/set.json.php accepts …

May 29, 2026
CVE-2026-45582
6.5 MEDIUM

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.3, the workflow telemetry sanitizer could …

May 29, 2026
CVE-2026-45580
5.4 MEDIUM

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability. The Live plugin's "YouTube-style" view renders …

May 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.