CVE Database

60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-105698
5.4 MEDIUM

Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.0.0 until 1.10.1, Langflow did not verify flow ownership in the deprecated …

Oct 5, 2026
CVE-2026-105447
5.5 MEDIUM

A flaw was found in Quay. When handling build trigger requests, the application incorrectly exposes trigger configuration details containing repository write tokens to global read-only …

Oct 5, 2026
CVE-2026-105444
6.3 MEDIUM

A security flaw has been discovered in dotnet eShop .NET 8. The impacted element is the function GetOrderAsync of the file src/Ordering.API/Apis/OrdersApi.cs of the component …

Oct 5, 2026
CVE-2026-105438
4.3 MEDIUM

A flaw has been found in O2OA up to 10.0.1-ce. This affects the function ActionUploadExcelWithUrl of the file /x_general_assemble_control/jaxrs/excel/upload/with/url of the component General Module. Executing …

Oct 5, 2026
CVE-2026-101893
4.4 MEDIUM

Newell Brands DYMO ID 1.5.1.71 parses job files using XmlDocument.Load() without disabling DTD processing. The PC Job Files view automatically parses every recognized job file …

Oct 5, 2026
CVE-2026-95264
6.5 MEDIUM

Feehi CMS 2.1.1 is vulnerable to Directory Traversal. An authenticated backend user with article edit permission can delete arbitrary files writable by the PHP process. …

Oct 5, 2026
CVE-2026-78862
6.8 MEDIUM

An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the UART serial interface on the printed circuit board (PCB)

Oct 5, 2026
CVE-2026-71299
6.5 MEDIUM

A flaw was found in Maestro. Its REST API write endpoints were registered without proper authentication middleware. This allows a remote attacker to perform unauthorized …

Oct 5, 2026
CVE-2026-71298
6.4 MEDIUM

A flaw was found in maestro. A remote attacker could exploit a SQL injection vulnerability in the `orderBy` query parameter of its REST API list …

Oct 5, 2026
CVE-2026-71297
5.4 MEDIUM

A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass …

Oct 5, 2026
CVE-2026-105696
6.5 MEDIUM

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-page RPC accepts a share-link permission object with blanket read access but does …

Oct 5, 2026
CVE-2026-105695
5.9 MEDIUM

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes …

Oct 5, 2026
CVE-2026-105694
5.4 MEDIUM

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, authenticated users with file-edit permission can upload SVG media whose scripts, event-handler attributes, and …

Oct 5, 2026
CVE-2026-105693
5.3 MEDIUM

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC returns every share-link row for a file even when the …

Oct 5, 2026
CVE-2026-105692
5.4 MEDIUM

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-share-link RPC retrieves a caller-selected share-link ID and verifies only that the caller …

Oct 5, 2026
CVE-2026-105690
5.9 MEDIUM

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, logout clears the browser's auth-token cookie without revoking the corresponding server-side session. A previously …

Oct 5, 2026
CVE-2026-105688
6.7 MEDIUM

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, create-team-invitations and the invitation acceptance path allow a non-owner team administrator to assign the …

Oct 5, 2026
CVE-2026-105687
4.9 MEDIUM

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-team-member RPC allows a team administrator to remove any member other than themselves …

Oct 5, 2026
CVE-2026-105684
4.3 MEDIUM

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-comment-threads, get-comment-thread, and get-comments RPC commands use check-comment-permissions! but do not apply the …

Oct 5, 2026
CVE-2026-105681
6.5 MEDIUM

Ghost is a Node.js content management system. From 5.9.0 until 6.44.1, an input validation issue allowed members to access comments they were not authorized to …

Oct 5, 2026
CVE-2026-105680
6.5 MEDIUM

Ghost is a Node.js content management system. From 5.81.0 until 6.60.0, staff with the Author role could delete posts and pages that they did not …

Oct 5, 2026
CVE-2026-105678
4.3 MEDIUM

Ghost is a Node.js content management system. From 0.5.0 until 6.64.0, staff users with the Editor or Super Editor role were able to assign their …

Oct 5, 2026
CVE-2026-105676
4.9 MEDIUM

Ghost is a Node.js content management system. From 1.20.0 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to …

Oct 5, 2026
CVE-2026-105648
4.0 MEDIUM

Ghost is a Node.js content management system. From 6.0.9 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abused by an …

Oct 5, 2026
CVE-2026-105647
4.0 MEDIUM

Ghost is a Node.js content management system. From 6.54.1 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abused by an …

Oct 5, 2026
CVE-2026-105389
6.3 MEDIUM

A security vulnerability has been detected in feelec-yishu feelcrm-os 1.0.0. This issue affects some unknown processing of the file App/Feelcrm/Crm/Controller/UploadController.class.php of the component UploadTicketFile Endpoint. …

Oct 5, 2026
CVE-2026-105388
6.3 MEDIUM

A weakness has been identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function index of the file App/Feelcrm/Index/Controller/MemberController.class.php of the component Member Endpoint. This …

Oct 5, 2026
CVE-2026-104030
5.5 MEDIUM

A flaw was found in sssd. This vulnerability allows a local user to cause a Denial of Service (DoS) by submitting a specially crafted passkey …

Oct 5, 2026
CVE-2026-103337
6.5 MEDIUM

Missing Authorization vulnerability in Kirillbdev WC Ukraine Shipping wc-ukr-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WC Ukraine Shipping: from n/a through …

Oct 5, 2026
CVE-2026-97304
6.5 MEDIUM

Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through 1.0.63.

Oct 5, 2026
CVE-2026-97275
5.3 MEDIUM

Improper Validation of Specified Quantity in Input vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Input Data Manipulation.This …

Oct 5, 2026
CVE-2026-95166
5.4 MEDIUM

In Bacularis v1.0.0 - 6.5.1 when adding a new pool, the LabelFormat field allows for a Cross Site Scripting (XSS) payload.

Oct 5, 2026
CVE-2026-95165
6.1 MEDIUM

Bacularis 5.4.0 - 6.5.1 is vulnerable to Cross Site Scripting (XSS) in the Organization name field.

Oct 5, 2026
CVE-2026-58834
5.5 MEDIUM

In setPermissionGrantState of DevicePolicyManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service …

Oct 5, 2026
CVE-2026-55265
6.5 MEDIUM

In multiple functions of PduParser.java, there is a possible out of bounds read due to a missing bounds check. This could lead to a remote …

Oct 5, 2026
CVE-2026-28667
5.5 MEDIUM

In multiple functions of rw_t5t.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with …

Oct 5, 2026
CVE-2026-105646
4.9 MEDIUM

Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, a crafted content import file could cause excessive CPU usage, making the Ghost server …

Oct 5, 2026
CVE-2026-105645
4.9 MEDIUM

Ghost is a Node.js content management system. From 5.37.0 until 6.67.0, a crafted request to the external media inliner could cause excessive CPU usage, making …

Oct 5, 2026
CVE-2026-105644
6.8 MEDIUM

Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, SVG images included in content imports were stored without sanitization. An attacker who convinced …

Oct 5, 2026
CVE-2026-104713
6.5 MEDIUM

Allocation of resources without limits or throttling vulnerability in the Apache Struts REST plugin. A request body is read into memory without any bound on …

Oct 5, 2026
CVE-2026-103086
6.5 MEDIUM

Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through 1.2.74.

Oct 5, 2026
CVE-2026-103085
6.5 MEDIUM

Improper Access Control vulnerability in WP User Manager WP User Manager wp-user-manager allows Privilege Abuse.This issue affects WP User Manager: from n/a through 2.9.20.

Oct 5, 2026
CVE-2026-102383
6.5 MEDIUM

Missing Authorization vulnerability in VillaTheme Lookzy woo-lookbook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lookzy: from n/a through 1.1.14.

Oct 5, 2026
CVE-2026-100509
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Stored XSS.This issue affects RepairBuddy: from n/a through …

Oct 5, 2026
CVE-2026-78413
5.5 MEDIUM

Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with elevated permissions. …

Oct 5, 2026
CVE-2026-78411
6.5 MEDIUM

Velociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server. This allows a user with LABEL_CLIENTS permission to update the server …

Oct 5, 2026
CVE-2026-42700
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Image Slider Widget image-slider-widget allows Stored XSS.This issue affects Image Slider Widget: …

Oct 5, 2026
CVE-2026-102576
4.2 MEDIUM

A flaw was found in Quay. A remote attacker could trick a user into logging in through a crafted link, resulting in cross-site scripting (XSS). …

Oct 5, 2026
CVE-2026-102295
5.4 MEDIUM

A flaw was found in Quay. A cross-site scripting (XSS) vulnerability in the OAuth callback handler allows a remote attacker to execute arbitrary JavaScript code …

Oct 5, 2026
CVE-2026-78412
4.9 MEDIUM

Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks the API permissions against the …

Oct 5, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.