CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-16799
5.0 MEDIUM

Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader …

Jul 24, 2026
CVE-2026-16798
6.5 MEDIUM

Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped …

Jul 24, 2026
CVE-2026-12504

Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local …

Jul 24, 2026
CVE-2026-12503

Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker …

Jul 24, 2026
CVE-2026-12502

Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker …

Jul 24, 2026
CVE-2026-12496

Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 …

Jul 24, 2026
CVE-2026-17048
5.5 MEDIUM

A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system …

Jul 24, 2026
CVE-2026-9765
7.1 HIGH

Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are “Broken” when a user can …

Jul 24, 2026
CVE-2026-7484
5.3 MEDIUM

External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects AVESİS: …

Jul 24, 2026
CVE-2026-66144
7.5 HIGH

Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service …

Jul 24, 2026
CVE-2026-66143
7.5 HIGH

It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may …

Jul 24, 2026
CVE-2026-66142
7.5 HIGH

Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial …

Jul 24, 2026
CVE-2026-66010
6.1 MEDIUM

DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive …

Jul 24, 2026
CVE-2026-66009

Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages that name required custom input fields even when …

Jul 24, 2026
CVE-2026-66008

Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target class names through GraphQL validation and input-coercion error …

Jul 24, 2026
CVE-2026-46452
5.3 MEDIUM

Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken data toward application resulting in memory pressure and …

Jul 24, 2026
CVE-2026-45816
7.5 HIGH

NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would trigger before NULL dereference) …

Jul 24, 2026
CVE-2026-45815
7.5 HIGH

Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser. Severity is medium as …

Jul 24, 2026
CVE-2026-45813
8.8 HIGH

Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS service "Add Source" and "Modify Source" operation …

Jul 24, 2026
CVE-2026-45812
6.5 MEDIUM

Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event. When a single HCI advertising report event bundles multiple …

Jul 24, 2026
CVE-2026-45811
7.5 HIGH

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether a received HCI …

Jul 24, 2026
CVE-2026-16743
5.5 MEDIUM

A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed …

Jul 24, 2026
CVE-2026-16730
5.5 MEDIUM

A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, …

Jul 24, 2026
CVE-2026-15810

A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, and 26.8.7 on Looker-hosted and Self-hosted …

Jul 24, 2026
CVE-2026-15243

Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches the configured allowlist or regex. An attacker …

Jul 24, 2026
CVE-2026-10610

Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user.

Jul 24, 2026
CVE-2026-7483

Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a privileged user.

Jul 24, 2026
CVE-2026-16634
9.8 CRITICAL

TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is no longer maintained, and has an uncontrolled …

Jul 24, 2026
CVE-2026-15663
4.9 MEDIUM

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' …

Jul 24, 2026
CVE-2026-15401
7.2 HIGH

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbfX' parameter in all versions up to, …

Jul 24, 2026
CVE-2026-10033
7.3 HIGH

The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the …

Jul 24, 2026
CVE-2026-63317
5.6 MEDIUM

Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected: - before 2.5.10 - before 3.0.0-M5 Description: Three code …

Jul 24, 2026
CVE-2026-56392

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. …

Jul 24, 2026
CVE-2026-56391

GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() …

Jul 24, 2026
CVE-2026-49745
7.8 HIGH

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the …

Jul 24, 2026
CVE-2026-49744
7.8 HIGH

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the …

Jul 24, 2026
CVE-2026-49743
7.8 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading …

Jul 24, 2026
CVE-2026-24727

An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote …

Jul 24, 2026
CVE-2026-15821
6.4 MEDIUM

The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, …

Jul 24, 2026
CVE-2026-15739
6.4 MEDIUM

The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all versions up to, and …

Jul 24, 2026
CVE-2026-15704
9.8 CRITICAL

In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between …

Jul 24, 2026
CVE-2026-15346
6.1 MEDIUM

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'category_id' parameter in all versions up to, …

Jul 24, 2026
CVE-2026-12702

In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.

Jul 24, 2026
CVE-2026-16910
5.5 MEDIUM

A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing …

Jul 24, 2026
CVE-2026-16519
7.3 HIGH

A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe …

Jul 24, 2026
CVE-2026-15755
6.4 MEDIUM

The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, …

Jul 24, 2026
CVE-2026-15665
6.4 MEDIUM

The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute in all …

Jul 24, 2026
CVE-2026-15653
6.4 MEDIUM

The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'backend-title' parameter in …

Jul 24, 2026
CVE-2026-15648
6.4 MEDIUM

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 …

Jul 24, 2026
CVE-2026-15464
6.4 MEDIUM

The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to, and including, 2.3.2 …

Jul 24, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.