CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-48393
7.8 HIGH

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this …

Jul 28, 2026
CVE-2026-48392
7.8 HIGH

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this …

Jul 28, 2026
CVE-2026-48391
8.2 HIGH

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged …

Jul 28, 2026
CVE-2026-48390
8.2 HIGH

Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and …

Jul 28, 2026
CVE-2026-48374
7.8 HIGH

Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. …

Jul 28, 2026
CVE-2026-18107
7.8 HIGH

A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an rseq critical section …

Jul 28, 2026
CVE-2026-16771
8.8 HIGH

In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side …

Jul 28, 2026
CVE-2026-16496
8.9 HIGH

The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another …

Jul 28, 2026
CVE-2026-15992
8.8 HIGH

The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing …

Jul 28, 2026
CVE-2026-14869
8.6 HIGH

The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to …

Jul 28, 2026
CVE-2026-59933
7.5 HIGH

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through …

Jul 28, 2026
CVE-2026-59931
7.7 HIGH

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through …

Jul 28, 2026
CVE-2026-54635
7.5 HIGH

pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.0.0 to 2.2.0, TonapiWebhookDispatcher fails …

Jul 28, 2026
CVE-2026-48388
8.6 HIGH

Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the …

Jul 28, 2026
CVE-2026-48372
7.8 HIGH

Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Jul 28, 2026
CVE-2026-67185
7.5 HIGH

TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting ../ sequences in the URL path, which …

Jul 28, 2026
CVE-2026-67184
7.5 HIGH

TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to crash worker processes by sending a malformed HTTP request line …

Jul 28, 2026
CVE-2026-67183
7.5 HIGH

TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well-formed HTTP requests. Each request causes …

Jul 28, 2026
CVE-2026-67182
7.5 HIGH

Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to bypass access controls by injecting bare line feed characters (0x0A) …

Jul 28, 2026
CVE-2026-54609
8.6 HIGH

QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding …

Jul 28, 2026
CVE-2026-54605
7.2 HIGH

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location …

Jul 28, 2026
CVE-2026-54603
8.6 HIGH

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location …

Jul 28, 2026
CVE-2026-16313
7.6 HIGH

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI …

Jul 28, 2026
CVE-2026-66748
8.8 HIGH

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code …

Jul 28, 2026
CVE-2026-61609
7.5 HIGH

Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProvider::configureRateLimiting() applied a single global bucket …

Jul 28, 2026
CVE-2026-54593
8.1 HIGH

Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid …

Jul 28, 2026
CVE-2026-54545
7.1 HIGH

wakaru is a JavaScript decompiler and unminifier toolkit. From 1.0.0 until 1.4.0, @wakaru/cli sanitizes bundle-controlled module filenames only once before writing extracted modules, so a …

Jul 28, 2026
CVE-2026-47483
8.2 HIGH

NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated …

Jul 28, 2026
CVE-2026-47427
7.5 HIGH

GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is nil, …

Jul 28, 2026
CVE-2026-45293
8.6 HIGH

WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the …

Jul 28, 2026
CVE-2026-43910
8.2 HIGH

Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. From 8.2.1 until 10.1.1, when directConnect(true) …

Jul 28, 2026
CVE-2026-8164
7.3 HIGH

Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client allows Search Order Hijacking. This issue affects ArkSigner …

Jul 28, 2026
CVE-2026-66299
7.5 HIGH

Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 …

Jul 28, 2026
CVE-2026-63727
8.8 HIGH

Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is …

Jul 28, 2026
CVE-2026-59878
7.5 HIGH

Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer that can reach an exposed AMQP NIO connector …

Jul 28, 2026
CVE-2026-7187
8.8 HIGH

Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects UKBS: through 28072026. …

Jul 28, 2026
CVE-2026-65881
7.5 HIGH

Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1 - The default configuration of the extension allowed …

Jul 28, 2026
CVE-2026-62433
7.3 HIGH

Parts of the DM_OP handling code assumes the caller has provided the required number of buffers for the given operation without any checking being done. …

Jul 28, 2026
CVE-2026-62432
7.3 HIGH

The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without holding the correct lock. It can race with EVTCHNOP_reset, resulting in dereferencing …

Jul 28, 2026
CVE-2026-62431
7.5 HIGH

The logic to handle periodic Viridian STIMERs performs a division with an unchecked user-controlled divisor value, that can be set to zero to cause a …

Jul 28, 2026
CVE-2026-62430
7.5 HIGH

Accesses to the CMOS memory contents are done using an indirect IO port pair. Therefore Xen needs to cache the guest chosen index, and one …

Jul 28, 2026
CVE-2026-62428
7.8 HIGH

When grant-copy operations are processed, the respective grant may or may not already be in use by another operation (a mapping or another copy). For …

Jul 28, 2026
CVE-2026-62427
8.8 HIGH

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operations …

Jul 28, 2026
CVE-2026-62426
8.8 HIGH

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operations …

Jul 28, 2026
CVE-2026-49332
8.5 HIGH

A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from …

Jul 28, 2026
CVE-2026-42493
7.5 HIGH

Addressing certain issues, in particular related to operations which may take excessively long and therefore would need preemption, has turned out overly costly. Since alternatives …

Jul 28, 2026
CVE-2026-42492
7.5 HIGH

Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To make this more robust, a new …

Jul 28, 2026
CVE-2026-15025
7.5 HIGH

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, …

Jul 28, 2026
CVE-2026-13440
7.2 HIGH

The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jul 28, 2026
CVE-2026-14785
7.5 HIGH

The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1.7.13 …

Jul 28, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.