CVE Database

48241+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-19223
7.2 HIGH

The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite …

Aug 27, 2026
CVE-2026-13415
7.2 HIGH

The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the …

Aug 27, 2026
CVE-2026-81491
7.3 HIGH

A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead …

Aug 27, 2026
CVE-2026-81421
7.3 HIGH

A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the …

Aug 27, 2026
CVE-2026-47852
7.5 HIGH

A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI …

Aug 27, 2026
CVE-2026-47851
7.5 HIGH

Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI …

Aug 27, 2026
CVE-2026-81203
7.3 HIGH

A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of …

Aug 26, 2026
CVE-2026-47666
7.6 HIGH

Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font …

Aug 26, 2026
CVE-2026-47665
8.7 HIGH

Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, …

Aug 26, 2026
CVE-2026-81202
7.3 HIGH

A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD …

Aug 26, 2026
CVE-2026-77611
7.1 HIGH

SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authenticated S3 principal with permissions scoped to a nested …

Aug 26, 2026
CVE-2026-77368
7.6 HIGH

SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a …

Aug 26, 2026
CVE-2026-77317
8.1 HIGH

SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a …

Aug 26, 2026
CVE-2026-75333
7.5 HIGH

yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path …

Aug 26, 2026
CVE-2026-75328
7.5 HIGH

In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitrary file read vulnerability:

Aug 26, 2026
CVE-2026-61617
7.7 HIGH

Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not …

Aug 26, 2026
CVE-2026-43621
8.1 HIGH

Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to …

Aug 26, 2026
CVE-2026-75415
7.5 HIGH

AntFlow V2.0.0 is vulnerable to Incorrect Access Control. JiMuMDCCommonsRequestLoggingFilter.java retrieves the userid from the request header as the core of the identity verification mechanism, allowing …

Aug 26, 2026
CVE-2026-75413
7.5 HIGH

DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize the downloadDocEx.do interface and download any …

Aug 26, 2026
CVE-2026-61792
7.7 HIGH

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their …

Aug 26, 2026
CVE-2026-55228
8.1 HIGH

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the …

Aug 26, 2026
CVE-2025-61480
7.5 HIGH

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP …

Aug 26, 2026
CVE-2025-61479
7.5 HIGH

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via the SPC …

Aug 26, 2026
CVE-2025-61478
7.5 HIGH

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via Spoofed SYN …

Aug 26, 2026
CVE-2025-51675
7.5 HIGH

An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate update of program counter (PC) values when SPR changes can lead to a Denial …

Aug 26, 2026
CVE-2026-79938
7.6 HIGH

Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, …

Aug 26, 2026
CVE-2026-77652
7.8 HIGH

A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer. In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette …

Aug 26, 2026
CVE-2026-74770
8.8 HIGH

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low …

Aug 26, 2026
CVE-2026-68863
7.5 HIGH

Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading …

Aug 26, 2026
CVE-2026-68861
8.8 HIGH

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low …

Aug 26, 2026
CVE-2026-46369
7.5 HIGH

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound …

Aug 26, 2026
CVE-2026-26449
7.5 HIGH

In Stomper 5e2741e when a client sends a SEND frame missing the destination header field, the server triggers a null pointer dereference (or access to …

Aug 26, 2026
CVE-2026-26447
7.5 HIGH

Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeatedly issues SUBSCRIBE commands for the same destination over one connection and then closes that …

Aug 26, 2026
CVE-2026-26446
7.5 HIGH

Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was already closed by the peer, …

Aug 26, 2026
CVE-2026-71171
7.2 HIGH

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in …

Aug 26, 2026
CVE-2026-36851
7.5 HIGH

Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.

Aug 26, 2026
CVE-2025-61164
7.5 HIGH

Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.

Aug 26, 2026
CVE-2025-61162
7.5 HIGH

Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted request to the /api/internal/v1/users/{{USER_ID}} endpoint

Aug 26, 2026
CVE-2026-58474
8.8 HIGH

whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to …

Aug 26, 2026
CVE-2026-47841
7.4 HIGH

An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store. Spring Security 7.1.0 Spring …

Aug 26, 2026
CVE-2026-47836
7.2 HIGH

The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config …

Aug 26, 2026
CVE-2025-56798
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication …

Aug 26, 2026
CVE-2025-29419
7.1 HIGH

CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.

Aug 26, 2026
CVE-2026-32258
8.1 HIGH

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor …

Aug 26, 2026
CVE-2026-32257
8.1 HIGH

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings …

Aug 26, 2026
CVE-2020-15878
8.8 HIGH

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a …

Aug 26, 2026
CVE-2020-15876
8.8 HIGH

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a …

Aug 26, 2026
CVE-2020-15874
8.8 HIGH

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the …

Aug 26, 2026
CVE-2026-81036
8.1 HIGH

Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success …

Aug 26, 2026
CVE-2026-81035
8.1 HIGH

Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises the caller with the team-access helper, which returns true …

Aug 26, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.