CVE Database

48241+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-38638
7.5 HIGH

An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.

Aug 28, 2026
CVE-2026-38636
7.5 HIGH

An issue in the seekdir() function (/dirent/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.

Aug 28, 2026
CVE-2026-37736
7.5 HIGH

An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Aug 28, 2026
CVE-2026-37237
7.5 HIGH

vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMediaIO.fetch_audio and AsyncMediaIO.fetch_image functions in multimodal/inputs.py …

Aug 28, 2026
CVE-2026-82261
7.5 HIGH

SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulnerability in form deserialization. An attacker can send …

Aug 28, 2026
CVE-2026-82260
7.5 HIGH

SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form …

Aug 28, 2026
CVE-2026-82259
7.5 HIGH

SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions …

Aug 28, 2026
CVE-2026-82254
7.5 HIGH

gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data …

Aug 28, 2026
CVE-2026-82253
7.5 HIGH

gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the …

Aug 28, 2026
CVE-2026-82252
7.5 HIGH

gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious …

Aug 28, 2026
CVE-2026-82251
7.5 HIGH

gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names …

Aug 28, 2026
CVE-2026-82247
7.5 HIGH

gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, …

Aug 28, 2026
CVE-2026-82246
7.1 HIGH

Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to validate user-supplied URLs before fetching content. Attackers …

Aug 28, 2026
CVE-2026-82245
8.1 HIGH

Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authenticated user to delete license keys or manipulate offline tokens. Attackers …

Aug 28, 2026
CVE-2026-82243
7.6 HIGH

Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users to supply arbitrary URLs without SSRF …

Aug 28, 2026
CVE-2026-82242
7.7 HIGH

Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpoint that allows authenticated builders to inject tables, automations, queries, and screens …

Aug 28, 2026
CVE-2026-82241
7.1 HIGH

Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 100.64.0.0/10 from its default SSRF blacklist (DEFAULT_BLACKLIST) used by REST datasource query …

Aug 28, 2026
CVE-2026-82240
8.1 HIGH

Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated app-scoped builder to grant …

Aug 28, 2026
CVE-2026-82239
8.1 HIGH

Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows …

Aug 28, 2026
CVE-2026-82234
8.2 HIGH

SiYuan versions before v3.8.1 contain a server-side request forgery vulnerability in the http_request and web_fetch agent tools that perform DNS resolution only at guard time …

Aug 28, 2026
CVE-2026-73208
7.4 HIGH

An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, …

Aug 28, 2026
CVE-2026-42391
7.5 HIGH

An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage …

Aug 28, 2026
CVE-2026-40018
7.4 HIGH

None None None No publicly available exploits are known.

Aug 28, 2026
CVE-2026-33605
7.5 HIGH

An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running in high-security mode (default for community …

Aug 28, 2026
CVE-2026-27852
7.5 HIGH

An attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresses or MIME …

Aug 28, 2026
CVE-2026-80724
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: prevent read-only mappings from becoming writable vmclock_miscdev_mmap() rejects writable mappings of the shared …

Aug 28, 2026
CVE-2026-80723
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: of: reserved_mem: prevent OOB when too many dynamic regions are defined On boot, fdt_scan_reserved_mem() saves …

Aug 28, 2026
CVE-2026-80722
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate individual TWT params before driver setup ieee80211_process_rx_twt_action() only partially validates a received …

Aug 28, 2026
CVE-2026-80721
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: ensure no dangling hcon references in iso_conn After iso_conn_del(), ISO sockets should not …

Aug 28, 2026
CVE-2026-80720
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: iomap: add a separate bio_set for iomap_split_ioend iomap_split_ioend can split bios that already come from …

Aug 28, 2026
CVE-2026-80718
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() In pcpu_create_chunk(), nr_pages is the total contiguous …

Aug 28, 2026
CVE-2026-80717
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: sctp: validate Adaptation Indication parameter length The Adaptation Layer Indication parameter contains a fixed 32-bit …

Aug 28, 2026
CVE-2026-80716
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: wake linked drain waiters on unlink snd_pcm_drain() on a linked stream parks an …

Aug 28, 2026
CVE-2026-80713
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: io_uring: preserve task restrictions across exec Per-task restrictions apply to all rings created by a …

Aug 28, 2026
CVE-2026-80712
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: spi: spi-qpic-snand: write the feature value before executing SET_FEATURE qcom_spi_send_cmdaddr() programs NAND_FLASH_CMD/NAND_EXEC_CMD and submits the …

Aug 28, 2026
CVE-2026-80710
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Fix undersized format-check buffer fmt_buffer_size in dasd_eckd_check_device_format() is declared as int, even though one …

Aug 28, 2026
CVE-2026-80709
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs There is a wrong upper limit …

Aug 28, 2026
CVE-2026-80707
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer Zero the allocated buffer in j1939_session_fresh_new() to ensure …

Aug 28, 2026
CVE-2026-80706
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: can: softing: fw_parse(): validate firmware record spans fw_parse() reads a fixed record header, a firmware-provided …

Aug 28, 2026
CVE-2026-80702
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size Two sites in vmwgfx_resource.c assign boolean literals to …

Aug 28, 2026
CVE-2026-80700
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: validate external BO copy bounds for both stride paths vmw_external_bo_copy() trusts caller-supplied offsets, strides, …

Aug 28, 2026
CVE-2026-80696
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: hwmon: (ltc4282) Fix reading the minimum alarm voltage Coverity reports an out-of-bounds access when reading …

Aug 28, 2026
CVE-2026-80692
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks There is theoretical UAF if the conn is …

Aug 28, 2026
CVE-2026-80691
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE In the iblock_execute_pr_out() function, …

Aug 28, 2026
CVE-2026-80685
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: mm/util: don't read __page_2 for order-1 folios in snapshot_page() snapshot_page() currently reads __page_2 after checking …

Aug 28, 2026
CVE-2026-80683
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: give the socket its own sco_conn reference sco_conn_del() drops a reference it does …

Aug 28, 2026
CVE-2026-80682
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: riscv/mm: use physical alignment for vmemmap_start_pfn RISC-V computes vmemmap_start_pfn by rounding phys_ram_base down to VMEMMAP_ADDR_ALIGN. …

Aug 28, 2026
CVE-2026-80680
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: i2c: amd-mp2: Unregister callback on adapter add failure amd_mp2_register_cb() stores the platform I2C context in …

Aug 28, 2026
CVE-2026-80678
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: i2c: imx: Fix slave registration race and error handling In i2c_imx_reg_slave(), the slave pointer was …

Aug 28, 2026
CVE-2026-80677
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() dev_has_sync_state() reads dev->driver twice without holding device_lock() …

Aug 28, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.