CVE Database

48241+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-86435
7.5 HIGH

commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft …

Sep 7, 2026
CVE-2026-86434
7.5 HIGH

league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeric-suffix search from 1 …

Sep 7, 2026
CVE-2026-86433
7.5 HIGH

commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Attributes extension where AttributesListener::findTargetAndDirection() performs quadratic-time sibling list scanning. Unauthenticated attackers …

Sep 7, 2026
CVE-2026-86431
7.2 HIGH

league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scripting vulnerability in the AttributesExtension. Prefixing an attribute name with a single U+000C form …

Sep 7, 2026
CVE-2026-86430
7.5 HIGH

league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform …

Sep 7, 2026
CVE-2026-86429
7.5 HIGH

The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly …

Sep 7, 2026
CVE-2026-86428
7.5 HIGH

commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous …

Sep 7, 2026
CVE-2026-86427
8.8 HIGH

LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows authenticated attackers to inject arbitrary rrdtool arguments by breaking out of …

Sep 7, 2026
CVE-2026-86306
7.3 HIGH

A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affects an unknown part of the file App/Home/Model/UserModel.class.php of the component Cookie Helper. Executing a …

Sep 7, 2026
CVE-2026-86305
7.3 HIGH

A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function Upload::upload of the file ThinkPHP/Library/Think/Upload.class.php. Performing a manipulation …

Sep 7, 2026
CVE-2026-86303
7.3 HIGH

A vulnerability was determined in 92181 markdown up to 058cab0cb7fb245a0ccc6b8446963ff8d573558f. Affected by this issue is the function lds of the file md.c. Executing a manipulation …

Sep 7, 2026
CVE-2026-80135
7.5 HIGH

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Check or Handling of Exceptional …

Sep 7, 2026
CVE-2026-80134
7.7 HIGH

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An …

Sep 7, 2026
CVE-2026-80133
7.4 HIGH

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated …

Sep 7, 2026
CVE-2026-80132
8.1 HIGH

ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. …

Sep 7, 2026
CVE-2026-79678
8.1 HIGH

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check …

Sep 7, 2026
CVE-2026-6431
7.2 HIGH

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Sep 7, 2026
CVE-2026-61409
7.3 HIGH

Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command …

Sep 7, 2026
CVE-2022-51017
7.5 HIGH

PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to exceed the 32767 …

Sep 7, 2026
CVE-2026-86404
8.8 HIGH

EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() method. However, by default both allow-list and …

Sep 7, 2026
CVE-2026-86300
7.3 HIGH

A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHandler of the component Web Management. This manipulation causes improper authentication. The …

Sep 7, 2026
CVE-2026-86298
7.3 HIGH

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /delete_subject.php. Performing a …

Sep 7, 2026
CVE-2026-86297
8.1 HIGH

A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. …

Sep 7, 2026
CVE-2026-86295
8.3 HIGH

A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the …

Sep 7, 2026
CVE-2026-86292
7.3 HIGH

A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown function of the file saveuser.php of the component User Creation. …

Sep 7, 2026
CVE-2026-86290
7.3 HIGH

A weakness has been identified in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /voting/ajax.php?action=save_category. This manipulation of the argument …

Sep 7, 2026
CVE-2026-86282
7.3 HIGH

A weakness has been identified in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected is an unknown function of the file travel/src/main/java/com/controller/CommonController.java of the component CommonDao. Executing …

Sep 7, 2026
CVE-2026-78254
7.4 HIGH

The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it …

Sep 7, 2026
CVE-2026-14296
7.5 HIGH

When using the Direct XIP update strategy, the main application image starts other cores (i.e. radio core), based on the currently active slot without additional …

Sep 7, 2026
CVE-2026-86277
7.3 HIGH

A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. Impacted is an unknown function of the file delete_exam.php. The manipulation …

Sep 7, 2026
CVE-2026-86276
7.3 HIGH

A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing …

Sep 7, 2026
CVE-2026-86273
7.3 HIGH

A weakness has been identified in projeto-siga siga up to 11.1.1. Affected by this issue is the function DownloadExterno.getUrl of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExUtilController.java of the …

Sep 7, 2026
CVE-2026-86272
7.3 HIGH

A vulnerability was determined in Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.6001.1096.1000. This impacts an unknown function of the file /Report/Upload/UploadFormImg.ashx. Executing a manipulation …

Sep 7, 2026
CVE-2026-86268
7.3 HIGH

A vulnerability was detected in itsourcecode School Management System 1.0. Impacted is an unknown function of the file User_Login.php. The manipulation of the argument email …

Sep 7, 2026
CVE-2026-86313
7.8 HIGH

Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.

Sep 7, 2026
CVE-2026-86263
7.3 HIGH

A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Cancellation. The …

Sep 7, 2026
CVE-2026-86262
7.3 HIGH

A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects the function updateOrderSta1/updateOrderdiseaseInfo of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order …

Sep 7, 2026
CVE-2026-86261
7.3 HIGH

A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The impacted element is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component …

Sep 7, 2026
CVE-2026-20502
8.4 HIGH

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Sep 7, 2026
CVE-2026-20501
8.4 HIGH

In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with …

Sep 7, 2026
CVE-2026-86225
7.3 HIGH

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The …

Sep 6, 2026
CVE-2026-86224
7.3 HIGH

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a manipulation of …

Sep 6, 2026
CVE-2026-86223
7.3 HIGH

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of the file /admin/modal_add_coursea.php. Performing a manipulation of …

Sep 6, 2026
CVE-2026-86222
7.3 HIGH

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. This affects the function mysqli_query of the file /admin/modal_add_course2.php. Such manipulation of …

Sep 6, 2026
CVE-2026-86221
7.3 HIGH

A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is the function mysqli_query of the file /admin/modal_add_course1.php. This …

Sep 6, 2026
CVE-2026-86220
7.3 HIGH

A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. The affected element is the function mysqli_query of the file /admin/modal_add_course.php. The manipulation …

Sep 6, 2026
CVE-2026-82209
8.2 HIGH

When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly …

Sep 6, 2026
CVE-2026-82208
7.5 HIGH

With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store after …

Sep 6, 2026
CVE-2026-80255
7.5 HIGH

A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store …

Sep 6, 2026
CVE-2026-80231
7.5 HIGH

A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store …

Sep 6, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.