CVE Database

48377+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-68513
7.1 HIGH

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions 3.3.0 through 3.3.12 and 3.4.0 …

Aug 25, 2026
CVE-2026-66153
7.0 HIGH

The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths.

Aug 25, 2026
CVE-2026-66152
8.8 HIGH

A Path traversal vulnerability in the SonicWall NetExtender Linux client file extractor component allows an attacker to write arbitrary file as root.

Aug 25, 2026
CVE-2026-59981
7.1 HIGH

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 …

Aug 25, 2026
CVE-2026-55099
7.5 HIGH

icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Component equality method in src/icalendar/cal/component.py compares …

Aug 25, 2026
CVE-2026-45019
7.2 HIGH

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose …

Aug 25, 2026
CVE-2026-43670
8.8 HIGH

A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, …

Aug 25, 2026
CVE-2026-80049
8.8 HIGH

Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. AuthorizationServerHandler copies recognised identifiers out of the raw JSON …

Aug 25, 2026
CVE-2026-79788
7.1 HIGH

In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required before_action on `defined?(Dradis::Pro)`, a constant that is never defined in CE, so the authorization …

Aug 25, 2026
CVE-2026-79786
7.1 HIGH

Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. …

Aug 25, 2026
CVE-2026-78379
8.1 HIGH

Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute …

Aug 25, 2026
CVE-2026-55620
7.5 HIGH

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to …

Aug 25, 2026
CVE-2026-55609
7.1 HIGH

sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear time. Prior to consciousness-explorer 1.1.2 and sublinear-time-solver 1.6.0, the export_state …

Aug 25, 2026
CVE-2026-79992
7.8 HIGH

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login …

Aug 25, 2026
CVE-2026-75770
7.8 HIGH

Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Aug 25, 2026
CVE-2026-75769
7.8 HIGH

Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-75768
7.8 HIGH

Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-75767
7.8 HIGH

Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-75766
7.8 HIGH

Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-75750
7.8 HIGH

Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-75749
7.8 HIGH

Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Aug 25, 2026
CVE-2026-71564
7.8 HIGH

Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Aug 25, 2026
CVE-2026-71443
7.5 HIGH

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to …

Aug 25, 2026
CVE-2026-71442
7.5 HIGH

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this …

Aug 25, 2026
CVE-2026-71399
7.8 HIGH

Adobe XD is affected by a Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. An attacker …

Aug 25, 2026
CVE-2026-71382
7.8 HIGH

Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Aug 25, 2026
CVE-2026-71360
7.5 HIGH

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust …

Aug 25, 2026
CVE-2026-59982
7.1 HIGH

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through …

Aug 25, 2026
CVE-2026-48433
7.8 HIGH

Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-48432
7.8 HIGH

Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-48431
7.8 HIGH

Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-48430
7.8 HIGH

Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-48428
7.8 HIGH

Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-48427
7.8 HIGH

Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Aug 25, 2026
CVE-2026-48426
7.8 HIGH

Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Aug 25, 2026
CVE-2026-48425
7.8 HIGH

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-48424
7.8 HIGH

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-48423
7.8 HIGH

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-48422
7.8 HIGH

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-48421
7.8 HIGH

Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Aug 25, 2026
CVE-2026-48420
7.8 HIGH

Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Aug 25, 2026
CVE-2026-48419
7.8 HIGH

Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Aug 25, 2026
CVE-2026-48418
7.8 HIGH

Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Aug 25, 2026
CVE-2026-48417
7.8 HIGH

Substance3D - Sampler is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. …

Aug 25, 2026
CVE-2026-75498
7.2 HIGH

Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to …

Aug 25, 2026
CVE-2026-75497
7.2 HIGH

Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to …

Aug 25, 2026
CVE-2026-75496
7.2 HIGH

Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, …

Aug 25, 2026
CVE-2026-64204
7.8 HIGH

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an …

Aug 25, 2026
CVE-2026-64203
7.8 HIGH

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an …

Aug 25, 2026
CVE-2026-64202
7.8 HIGH

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an …

Aug 25, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.