CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-48210
5.7 MEDIUM

An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default and prevent users …

May 31, 2026
CVE-2026-10194
6.3 MEDIUM

A weakness has been identified in OFFIS DCMTK 3.7.0. This affects the function DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages of the file dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. Executing a manipulation …

May 31, 2026
CVE-2026-10193
6.3 MEDIUM

A security flaw has been discovered in OFCMS up to 1.1.3. The impacted element is the function Query of the file ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\ComnController.java of the component …

May 31, 2026
CVE-2026-10190
6.5 MEDIUM

A vulnerability was found in Tenda W12 3.0.0.7(4763). This issue affects the function cgiSysWebTimeoutSet of the file /bin/httpd of the component Web Management Interface. The …

May 31, 2026
CVE-2026-10182
6.3 MEDIUM

A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formWlanSetup of the file /goform/formWlanSetup. Executing a manipulation of the argument …

May 31, 2026
CVE-2026-10180
6.3 MEDIUM

A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSysCmd of the file /goform/formSysCmd. Such manipulation of the argument sysCmd leads …

May 31, 2026
CVE-2026-10177
6.3 MEDIUM

A security vulnerability has been detected in Aider-AI Aider 0.86.3. This affects the function requests.get of the file api_docs.py of the component AWS EC2 Metadata …

May 31, 2026
CVE-2026-10176
6.3 MEDIUM

A weakness has been identified in Aider-AI Aider 0.86.3. Affected by this issue is some unknown functionality of the component Code Generation Workflow. Executing a …

May 31, 2026
CVE-2026-10175
6.3 MEDIUM

A security flaw has been discovered in Aider-AI Aider 0.86.3. Affected by this vulnerability is the function editor_coder.run of the file auth.py of the component …

May 31, 2026
CVE-2026-10174
6.3 MEDIUM

A vulnerability was identified in Aider-AI Aider 0.86.3. Affected is an unknown function of the file aider/args.py of the component Pre-commit Hook Handler. Such manipulation …

May 31, 2026
CVE-2026-10173
4.3 MEDIUM

A weakness has been identified in Orthanc Explorer 2 up to 1.12.0. The impacted element is an unknown function of the file WebApplication/src/components/StudyList.vue of the …

May 31, 2026
CVE-2026-10172
6.3 MEDIUM

A security flaw has been discovered in Bdtask Multi-Store Inventory Management System 1.0. The affected element is the function Upload of the file application/modules/dashboard/controllers/Module.php of …

May 31, 2026
CVE-2026-10171
4.7 MEDIUM

A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminUpdateAlbum.php. Such manipulation of the argument …

May 31, 2026
CVE-2026-10170
6.3 MEDIUM

A flaw has been found in code-projects Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /vms/php/phone_0.php. This manipulation …

May 31, 2026
CVE-2026-10168
6.3 MEDIUM

A security vulnerability has been detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. Affected is the function marks of the file application/controllers/Parents.php. The …

May 31, 2026
CVE-2026-8382
5.3 MEDIUM

The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due to …

May 31, 2026
CVE-2026-10166
6.3 MEDIUM

A vulnerability was determined in Edimax BR-6478AC 1.23. The affected element is the function formWlbasic of the file /goform/formWlbasic of the component POST Request Handler. …

May 31, 2026
CVE-2026-10156
4.3 MEDIUM

A vulnerability was determined in Open5GS up to 2.7.7. This affects the function handle_amf_info in the library /lib/sbi/nnrf-handler.c of the component nf-instances Endpoint. Executing a …

May 31, 2026
CVE-2026-10155
4.7 MEDIUM

A vulnerability was found in Bdtask Multi-Store Inventory Management System 1.0. The impacted element is the function accounts_report_search of the file application/modules/accounts/controllers/Accounts.php of the component …

May 31, 2026
CVE-2026-10154
4.3 MEDIUM

A vulnerability has been found in Dolibarr ERP CRM 23.0.0/23.0.1/23.0.2. The affected element is an unknown function of the file htdocs/user/messaging.php. Such manipulation of the …

May 31, 2026
CVE-2026-10153
4.3 MEDIUM

A flaw has been found in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. Impacted is the function Search of the file org/springframework/cache/support/AbstractCacheManager.java. This manipulation of the argument …

May 30, 2026
CVE-2026-10152
6.3 MEDIUM

A vulnerability was detected in TaleLin lin-cms-spring-boot up to 0.2.1. This issue affects some unknown processing of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. …

May 30, 2026
CVE-2026-10127
6.3 MEDIUM

A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. This …

May 30, 2026
CVE-2026-8594
6.2 MEDIUM

Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters. Text::LineFold splits the input string by specific line …

May 30, 2026
CVE-2018-25423
6.2 MEDIUM

Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste …

May 30, 2026
CVE-2018-25421
6.5 MEDIUM

Open STA Manager 2.3 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by manipulating the file parameter. Attackers can send …

May 30, 2026
CVE-2026-10117
4.3 MEDIUM

A weakness has been identified in Open5GS up to 2.7.7. This issue affects the function ogs_pool_id_calloc in the library /lib/sbi/nghttp2-server.c. Executing a manipulation can lead …

May 30, 2026
CVE-2026-10116
4.3 MEDIUM

A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_sbi_xact_add in the library /lib/core/ogs-timer.c of the component ue-authentications …

May 30, 2026
CVE-2026-10115
4.3 MEDIUM

A vulnerability was identified in Open5GS up to 2.7.7. This affects an unknown part in the library lib/sbi/nnrf-handler.c of the component Shared NF-profile Parser. Such …

May 30, 2026
CVE-2026-10114
4.3 MEDIUM

A vulnerability was determined in Open5GS up to 2.7.7. Affected by this issue is the function handle_scp_info in the library lib/sbi/nnrf-handler.c of the component Shared …

May 30, 2026
CVE-2026-10113
4.3 MEDIUM

A vulnerability was found in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality in the library lib/sbi/nnrf-handler.c of the component Shared …

May 30, 2026
CVE-2026-5071
6.1 MEDIUM

The SocketCAN implementation validates the length of a user-provided buffer containing a socketcan_frame object using only a NET_ASSERT statement in zcan_sendto_ctx() before dereferencing it in …

May 30, 2026
CVE-2026-48840
5.3 MEDIUM

Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.

May 30, 2026
CVE-2026-9831
6.3 MEDIUM

A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-concurrency traffic conditions, intermittently allow requests authenticated with …

May 29, 2026
CVE-2026-48811
4.3 MEDIUM

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, FreeScout allows a non-admin user to permanently delete …

May 29, 2026
CVE-2026-48810
4.3 MEDIUM

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, while investigating the ThreadPolicy::delete issue reported previously, the …

May 29, 2026
CVE-2026-45352
5.3 MEDIUM

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size in chunked Transfer-Encoding causes unbounded memory allocation and process crash. …

May 29, 2026
CVE-2026-45294
5.3 MEDIUM

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset endpoint returns visually distinct responses …

May 29, 2026
CVE-2026-45149
6.5 MEDIUM

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. …

May 29, 2026
CVE-2026-44640
4.5 MEDIUM

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->prov_data is stored as nni_quic_conn* during dialing, but read as ex_quic_conn* during …

May 29, 2026
CVE-2026-44287
6.3 MEDIUM

FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at projects/code-sandbox/src/pool/worker.ts:356 blocks dynamic import() with the regex /\bimport\s*\(/.test(code). JavaScript syntax …

May 29, 2026
CVE-2026-42500
5.3 MEDIUM

Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image.

May 29, 2026
CVE-2026-34127
4.8 MEDIUM

A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG108PE v5 switch due to improper sanitation of the …

May 29, 2026
CVE-2026-49386
6.5 MEDIUM

In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas

May 29, 2026
CVE-2026-49385
6.5 MEDIUM

In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts

May 29, 2026
CVE-2026-49384
6.1 MEDIUM

In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible

May 29, 2026
CVE-2026-49382
4.5 MEDIUM

In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin

May 29, 2026
CVE-2026-49379
6.5 MEDIUM

In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names

May 29, 2026
CVE-2026-49378
4.3 MEDIUM

In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion

May 29, 2026
CVE-2026-49377
4.3 MEDIUM

In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters

May 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.