CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-69253

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and …

Aug 4, 2026
CVE-2026-69252

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only …

Aug 4, 2026
CVE-2026-69110
9.1 CRITICAL

OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by …

Aug 4, 2026
CVE-2026-69100
8.8 HIGH

LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database …

Aug 4, 2026
CVE-2026-69098
9.8 CRITICAL

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON …

Aug 4, 2026
CVE-2026-25292
7.6 HIGH

Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.

Aug 4, 2026
CVE-2026-25289
9.6 CRITICAL

Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.

Aug 4, 2026
CVE-2026-25288
7.4 HIGH

Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.

Aug 4, 2026
CVE-2026-24084
7.5 HIGH

Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.

Aug 4, 2026
CVE-2026-24083
7.8 HIGH

Memory Corruption while processing IOCTL device driver requests with invalid arguments.

Aug 4, 2026
CVE-2026-24080
7.8 HIGH

Memory Corruption when handling malformed request parameters in the fingerprint TA.

Aug 4, 2026
CVE-2026-24079
8.1 HIGH

Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.

Aug 4, 2026
CVE-2026-24078
6.5 MEDIUM

Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.

Aug 4, 2026
CVE-2026-24077
6.5 MEDIUM

Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.

Aug 4, 2026
CVE-2026-24076
6.7 MEDIUM

Memory Corruption when processing registry values with incorrect types using a direct query method.

Aug 4, 2026
CVE-2026-21366
7.8 HIGH

Memory corruption while processing a packet with a size close to the maximum allowed value.

Aug 4, 2026
CVE-2026-18801

OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution values. An attacker who can create or update a customer …

Aug 4, 2026
CVE-2026-18773
6.3 MEDIUM

A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component …

Aug 4, 2026
CVE-2026-10032

The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript: URI …

Aug 4, 2026
CVE-2026-69251

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory …

Aug 4, 2026
CVE-2026-69250

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST …

Aug 4, 2026
CVE-2026-68494

The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the …

Aug 4, 2026
CVE-2026-67618
6.5 MEDIUM

marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operator API keys by embedding a malicious base_url in PEP-723 inline …

Aug 4, 2026
CVE-2026-67200
7.5 HIGH

Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files from the server filesystem by including literal ../ segments …

Aug 4, 2026
CVE-2026-67199
6.5 MEDIUM

Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a crafted expression containing …

Aug 4, 2026
CVE-2026-67198
7.5 HIGH

Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to crash the server process by sending malformed or …

Aug 4, 2026
CVE-2026-67196
5.4 MEDIUM

Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to inject arbitrary HTML and JavaScript by writing table cell …

Aug 4, 2026
CVE-2026-67195
8.8 HIGH

Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the …

Aug 4, 2026
CVE-2026-61515
9.8 CRITICAL

Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by …

Aug 4, 2026
CVE-2026-61514
9.8 CRITICAL

Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets …

Aug 4, 2026
CVE-2026-18770
7.3 HIGH

A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /code of the component Python Validation …

Aug 4, 2026
CVE-2026-18766
6.3 MEDIUM

A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affects some unknown processing of the file /Applications/MAMP/htdocs/core-php-admin-panel-master/customers.php. Executing a manipulation of …

Aug 4, 2026
CVE-2026-18650
8.8 HIGH

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MYS: from 2.2.3 before 2.3.1.

Aug 4, 2026
CVE-2026-18401

The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON …

Aug 4, 2026
CVE-2026-11368
7.1 HIGH

The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data->att_chan = chan). When …

Aug 4, 2026
CVE-2026-70368
6.5 MEDIUM

A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A remote attacker with network access …

Aug 4, 2026
CVE-2026-70367
5.4 MEDIUM

A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to …

Aug 4, 2026
CVE-2026-17070
8.8 HIGH

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: from 2.2.3 before 2.3.1.

Aug 4, 2026
CVE-2026-14337

Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user …

Aug 4, 2026
CVE-2026-70373
8.8 HIGH

Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concatenating several user-controlled request parameters directly into the SQL string. The …

Aug 4, 2026
CVE-2026-70372
8.8 HIGH

Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Criteria parameter is only normalized …

Aug 4, 2026
CVE-2026-70371
8.8 HIGH

Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Line and Column parameters are …

Aug 4, 2026
CVE-2026-70370
8.8 HIGH

Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directly into identifier positions of the query (SELECT …

Aug 4, 2026
CVE-2026-70369
8.8 HIGH

Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-controlled Filter request parameters directly into WHERE fragments covering aqbasket.closedate, aqorders.datereceived, aqbooksellers.name, …

Aug 4, 2026
CVE-2026-63252
7.5 HIGH

In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote …

Aug 4, 2026
CVE-2026-63248
6.5 MEDIUM

In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a …

Aug 4, 2026
CVE-2026-62927
7.5 HIGH

In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or …

Aug 4, 2026
CVE-2026-61387
7.5 HIGH

In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is …

Aug 4, 2026
CVE-2026-60007
7.4 HIGH

In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path …

Aug 4, 2026
CVE-2026-58080
8.2 HIGH

In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running …

Aug 4, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.