CVE Database

60653+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-70593
6.6 MEDIUM

Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of …

Aug 4, 2026
CVE-2026-70592
5.5 MEDIUM

Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database …

Aug 4, 2026
CVE-2026-70591
4.1 MEDIUM

Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to …

Aug 4, 2026
CVE-2026-70590
4.8 MEDIUM

Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through …

Aug 4, 2026
CVE-2026-70589
4.8 MEDIUM

Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer …

Aug 4, 2026
CVE-2026-52370
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the …

Aug 4, 2026
CVE-2026-51144
6.1 MEDIUM

Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via the Role Name, First …

Aug 4, 2026
CVE-2026-18816
5.0 MEDIUM

A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of the component 2FA …

Aug 4, 2026
CVE-2026-70588
5.0 MEDIUM

Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting …

Aug 4, 2026
CVE-2026-70493
6.5 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tools/knowledge_fs.py and backend/open_webui/tools/builtin.py let …

Aug 4, 2026
CVE-2026-70491
6.5 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /api/v1/tools/, GET /api/v1/tools/list, and GET /api/v1/tools/id/{id} endpoints in …

Aug 4, 2026
CVE-2026-70490
6.3 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backend/open_webui/routers/terminals.py authenticated its own first-message …

Aug 4, 2026
CVE-2026-70489
6.5 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backend/open_webui/utils/automations.py anchored minutely and hourly rules …

Aug 4, 2026
CVE-2026-70488
4.3 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge …

Aug 4, 2026
CVE-2026-70487
5.3 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted client-supplied knowledge attachments without filtering …

Aug 4, 2026
CVE-2026-54020
6.3 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL validation and rejected private, …

Aug 4, 2026
CVE-2026-70484
4.3 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-supplied image_generation flag …

Aug 4, 2026
CVE-2026-70481
5.4 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any …

Aug 4, 2026
CVE-2026-70480
4.1 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open WebUI renders vega and vega-lite fenced code blocks in …

Aug 4, 2026
CVE-2026-48154
5.9 MEDIUM

GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA contains a …

Aug 4, 2026
CVE-2026-16792
6.1 MEDIUM

An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive …

Aug 4, 2026
CVE-2026-69704
6.5 MEDIUM

Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsanitized input through a GET parameter to the supp() deletion …

Aug 4, 2026
CVE-2026-69702
6.5 MEDIUM

SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated attackers to crash the server by supplying a crafted Zstandard-compressed …

Aug 4, 2026
CVE-2026-68743
5.5 MEDIUM

A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before …

Aug 4, 2026
CVE-2026-66300
5.0 MEDIUM

SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. An attacker can inject arbitrary JavaScript which will execute upon a …

Aug 4, 2026
CVE-2026-47622
5.3 MEDIUM

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive information. A successful exploit of …

Aug 4, 2026
CVE-2026-47621
6.5 MEDIUM

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of …

Aug 4, 2026
CVE-2026-47620
6.5 MEDIUM

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of …

Aug 4, 2026
CVE-2026-47619
6.6 MEDIUM

NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might …

Aug 4, 2026
CVE-2026-47487
4.4 MEDIUM

NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or …

Aug 4, 2026
CVE-2026-48121
6.7 MEDIUM

@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and below are vulnerable to NoSQL injection: checkpoint identifiers (thread_id, checkpoint_ns, checkpoint_id) …

Aug 4, 2026
CVE-2026-18785
5.3 MEDIUM

A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a manipulation can lead to use after …

Aug 4, 2026
CVE-2026-18784
5.3 MEDIUM

A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute of the file src/client/ua_client_highlevel.c. Performing a manipulation results in …

Aug 4, 2026
CVE-2026-18775
6.3 MEDIUM

A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/browser_tool.py of the component Browser …

Aug 4, 2026
CVE-2026-18774
6.3 MEDIUM

A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the component xAI Image …

Aug 4, 2026
CVE-2026-15920
6.1 MEDIUM

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating …

Aug 4, 2026
CVE-2026-15830
5.3 MEDIUM

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested …

Aug 4, 2026
CVE-2026-15337
5.3 MEDIUM

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, …

Aug 4, 2026
CVE-2026-24078
6.5 MEDIUM

Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.

Aug 4, 2026
CVE-2026-24077
6.5 MEDIUM

Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.

Aug 4, 2026
CVE-2026-24076
6.7 MEDIUM

Memory Corruption when processing registry values with incorrect types using a direct query method.

Aug 4, 2026
CVE-2026-18773
6.3 MEDIUM

A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component …

Aug 4, 2026
CVE-2026-67618
6.5 MEDIUM

marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operator API keys by embedding a malicious base_url in PEP-723 inline …

Aug 4, 2026
CVE-2026-67199
6.5 MEDIUM

Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a crafted expression containing …

Aug 4, 2026
CVE-2026-67196
5.4 MEDIUM

Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to inject arbitrary HTML and JavaScript by writing table cell …

Aug 4, 2026
CVE-2026-18766
6.3 MEDIUM

A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affects some unknown processing of the file /Applications/MAMP/htdocs/core-php-admin-panel-master/customers.php. Executing a manipulation of …

Aug 4, 2026
CVE-2026-70368
6.5 MEDIUM

A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A remote attacker with network access …

Aug 4, 2026
CVE-2026-70367
5.4 MEDIUM

A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to …

Aug 4, 2026
CVE-2026-63248
6.5 MEDIUM

In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a …

Aug 4, 2026
CVE-2026-18809
6.5 MEDIUM

Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153.0.3.

Aug 4, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.