CVE Database

48241+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-58566
8.8 HIGH

Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

Sep 1, 2026
CVE-2026-84268
8.8 HIGH

A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() …

Sep 1, 2026
CVE-2026-84203
8.1 HIGH

Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with …

Sep 1, 2026
CVE-2026-84202
8.8 HIGH

ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories …

Sep 1, 2026
CVE-2026-84201
7.1 HIGH

appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and write_files_batch tools, allowing attackers to write files outside the intended PROJECT_ROOT …

Sep 1, 2026
CVE-2026-79682
8.8 HIGH

Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.

Sep 1, 2026
CVE-2026-61779
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61778
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61777
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61776
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61775
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61774
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61773
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61772
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61771
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61770
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61769
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61768
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61767
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61766
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61765
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61764
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61763
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61762
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61761
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61760
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61759
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61758
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61757
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61756
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61755
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61754
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61753
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61752
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61751
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61750
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-58567
8.8 HIGH

Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root …

Sep 1, 2026
CVE-2026-49329
7.5 HIGH

A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to golang.org/x/text/language.ParseAcceptLanguage() without input validation. A bypass …

Sep 1, 2026
CVE-2026-10195
8.8 HIGH

The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 8.0.1. This is due to insufficient input sanitization …

Sep 1, 2026
CVE-2026-84233
7.0 HIGH

A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated …

Sep 1, 2026
CVE-2026-84115
8.3 HIGH

A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT …

Sep 1, 2026
CVE-2026-84111
7.3 HIGH

A flaw has been found in Chanjet CRM up to 20260707. This issue affects some unknown processing of the file jxf_dump_table.php. This manipulation of the …

Sep 1, 2026
CVE-2026-79686
8.8 HIGH

Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain …

Sep 1, 2026
CVE-2026-58569
8.8 HIGH

Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute …

Sep 1, 2026
CVE-2026-18780
7.1 HIGH

Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Cross Site Request Forgery. This issue affects …

Sep 1, 2026
CVE-2026-18771
7.5 HIGH

Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass. This issue affects Talassoft …

Sep 1, 2026
CVE-2026-18630
8.8 HIGH

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software …

Sep 1, 2026
CVE-2026-84218
8.1 HIGH

A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to …

Sep 1, 2026
CVE-2026-79684
8.8 HIGH

Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain …

Sep 1, 2026
CVE-2026-58572
8.8 HIGH

Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges.

Sep 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.