CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-64794
6.5 MEDIUM

Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and conditions allowed access to insufficiently …

Jul 22, 2026
CVE-2026-64793
9.1 CRITICAL

Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or …

Jul 22, 2026
CVE-2026-64792
7.5 HIGH

Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions - Smart Search indexing could render generated content …

Jul 22, 2026
CVE-2026-64791
8.8 HIGH

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not …

Jul 22, 2026
CVE-2026-63685
8.8 HIGH

Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacement requests did not consistently require Super User permission and …

Jul 22, 2026
CVE-2026-63684
8.8 HIGH

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator actions, editor …

Jul 22, 2026
CVE-2026-63683
7.5 HIGH

Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote …

Jul 22, 2026
CVE-2026-63281
4.8 MEDIUM

Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager - Stored condition values could also execute HTML/JavaScript in administrator summaries.

Jul 22, 2026
CVE-2026-63280
8.8 HIGH

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently enforce tokens …

Jul 22, 2026
CVE-2026-63265
8.0 HIGH

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged Regular Labs AJAX endpoints …

Jul 22, 2026
CVE-2026-13089
7.5 HIGH

OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify. When the caller does not pin …

Jul 22, 2026
CVE-2025-60835
7.8 HIGH

An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.

Jul 22, 2026
CVE-2025-50330
8.8 HIGH

An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.

Jul 22, 2026
CVE-2025-50329
9.8 CRITICAL

An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.

Jul 22, 2026
CVE-2025-50327
8.8 HIGH

An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the …

Jul 22, 2026
CVE-2025-50325
5.4 MEDIUM

BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of BandiZip

Jul 22, 2026
CVE-2025-50324
8.8 HIGH

An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.

Jul 22, 2026
CVE-2025-44090
8.8 HIGH

An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.

Jul 22, 2026
CVE-2025-44089
8.8 HIGH

An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.

Jul 22, 2026
CVE-2026-9737
6.5 MEDIUM

During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may …

Jul 22, 2026
CVE-2026-64829
7.4 HIGH

Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by exploiting the forgot-password …

Jul 22, 2026
CVE-2026-14899
7.5 HIGH

The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, …

Jul 22, 2026
CVE-2026-14881
7.8 HIGH

When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it …

Jul 22, 2026
CVE-2026-13078
7.7 HIGH

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read …

Jul 22, 2026
CVE-2026-13077
7.1 HIGH

A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pipeline. The …

Jul 22, 2026
CVE-2026-13076
6.5 MEDIUM

An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion …

Jul 22, 2026
CVE-2026-13075
6.5 MEDIUM

An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusion aggregation stages. …

Jul 22, 2026
CVE-2026-13074
5.3 MEDIUM

An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command …

Jul 22, 2026
CVE-2026-13073
4.3 MEDIUM

An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command, resulting in denial of service …

Jul 22, 2026
CVE-2026-13072
8.1 HIGH

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory …

Jul 22, 2026
CVE-2026-13071
6.5 MEDIUM

An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side JavaScript. The issue involves …

Jul 22, 2026
CVE-2026-13070
5.3 MEDIUM

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. …

Jul 22, 2026
CVE-2026-13069
6.5 MEDIUM

An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an …

Jul 22, 2026
CVE-2026-13068
4.2 MEDIUM

An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongoing query …

Jul 22, 2026
CVE-2026-13067
6.3 MEDIUM

When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured …

Jul 22, 2026
CVE-2026-13066
6.5 MEDIUM

Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in data returned …

Jul 22, 2026
CVE-2026-13065
6.5 MEDIUM

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to …

Jul 22, 2026
CVE-2026-13064
6.5 MEDIUM

Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in affected MongoDB deployments, potentially leading to resource exhaustion. The resulting CPU-bound …

Jul 22, 2026
CVE-2026-13063
4.3 MEDIUM

An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-memory condition by sending a crafted aggregation command. …

Jul 22, 2026
CVE-2026-13062
6.5 MEDIUM

An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be …

Jul 22, 2026
CVE-2026-13061
4.3 MEDIUM

An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is …

Jul 22, 2026
CVE-2026-13060
6.5 MEDIUM

An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency …

Jul 22, 2026
CVE-2026-13059
8.1 HIGH

An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to …

Jul 22, 2026
CVE-2026-13058

An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with an incomplete set …

Jul 22, 2026
CVE-2026-13057
5.3 MEDIUM

An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In sharded topologies, the $search and $searchMeta aggregation …

Jul 22, 2026
CVE-2026-13056
6.5 MEDIUM

Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to …

Jul 22, 2026
CVE-2026-13055
6.5 MEDIUM

The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to handle compound wildcard index …

Jul 22, 2026
CVE-2026-3482
5.3 MEDIUM

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 could allow an unauthenticated user to …

Jul 22, 2026
CVE-2026-22049

ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully …

Jul 22, 2026
CVE-2026-16624
9.6 CRITICAL

Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then …

Jul 22, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.