CVE Database

60653+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-10600
4.3 MEDIUM

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document …

Jul 27, 2026
CVE-2026-17514
5.3 MEDIUM

A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Extract of the file lib/extract.js. This manipulation causes …

Jul 27, 2026
CVE-2026-15003
5.6 MEDIUM

A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted …

Jul 27, 2026
CVE-2026-66053
5.9 MEDIUM

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade …

Jul 27, 2026
CVE-2026-55970
6.5 MEDIUM

Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes …

Jul 27, 2026
CVE-2026-17534
5.5 MEDIUM

Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTarget, without resolving DNS or re-validating hosts after …

Jul 27, 2026
CVE-2026-66412
6.5 MEDIUM

Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone data from projects they are not assigned to …

Jul 27, 2026
CVE-2026-14827
6.8 MEDIUM

The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, …

Jul 27, 2026
CVE-2026-14820
5.3 MEDIUM

The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and …

Jul 27, 2026
CVE-2026-14568
6.5 MEDIUM

The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership …

Jul 27, 2026
CVE-2026-14236
4.7 MEDIUM

The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and …

Jul 27, 2026
CVE-2026-14203
4.8 MEDIUM

The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, …

Jul 27, 2026
CVE-2026-14190
6.1 MEDIUM

The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticated AJAX handlers …

Jul 27, 2026
CVE-2026-13400
6.1 MEDIUM

Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: …

Jul 27, 2026
CVE-2026-13390
5.3 MEDIUM

The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips …

Jul 27, 2026
CVE-2026-12982
6.1 MEDIUM

The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated …

Jul 27, 2026
CVE-2026-10082
6.1 MEDIUM

The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it in the page, allowing users with the …

Jul 27, 2026
CVE-2026-17501
5.3 MEDIUM

A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. This …

Jul 27, 2026
CVE-2026-17500
5.3 MEDIUM

A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation results in null pointer dereference. The …

Jul 27, 2026
CVE-2026-57978
5.4 MEDIUM

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Jul 26, 2026
CVE-2026-17459
4.3 MEDIUM

A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.jav of the component SparkJava. Executing …

Jul 26, 2026
CVE-2026-17458
6.3 MEDIUM

A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP …

Jul 26, 2026
CVE-2026-17457
4.3 MEDIUM

A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the …

Jul 26, 2026
CVE-2026-17434
6.3 MEDIUM

A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing …

Jul 26, 2026
CVE-2026-17433
5.3 MEDIUM

A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. …

Jul 26, 2026
CVE-2026-17432
5.0 MEDIUM

A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway …

Jul 26, 2026
CVE-2026-10681
6.5 MEDIUM

In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thread permission index from the global _thread_idx_map[] bitmap without holding lists_lock. On SMP systems, …

Jul 25, 2026
CVE-2026-15425
6.4 MEDIUM

The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Slug (post_name) …

Jul 25, 2026
CVE-2026-14955
6.5 MEDIUM

The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the …

Jul 25, 2026
CVE-2026-66339
6.5 MEDIUM

A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS …

Jul 24, 2026
CVE-2026-66338
5.4 MEDIUM

A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC …

Jul 24, 2026
CVE-2026-66337
6.5 MEDIUM

A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A …

Jul 24, 2026
CVE-2026-61886
6.5 MEDIUM

Weintek cMT3092X HMI stores user account passwords in plaintext.

Jul 24, 2026
CVE-2026-60135
6.5 MEDIUM

An attacker can modify data that should be restricted to read‑only access.

Jul 24, 2026
CVE-2026-55985
4.3 MEDIUM

The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any …

Jul 24, 2026
CVE-2026-66038
6.5 MEDIUM

FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory …

Jul 24, 2026
CVE-2026-66037
6.5 MEDIUM

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte …

Jul 24, 2026
CVE-2026-57531
5.4 MEDIUM

Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows unauthenticated attackers to execute arbitrary JavaScript in the host application's …

Jul 24, 2026
CVE-2026-57530
5.4 MEDIUM

Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary …

Jul 24, 2026
CVE-2026-65707
6.5 MEDIUM

Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract arbitrary database contents by submitting unsanitized POST parameters to the …

Jul 24, 2026
CVE-2026-8308
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services Website Template allows Reflected XSS. This issue …

Jul 24, 2026
CVE-2026-7007
4.6 MEDIUM

The Zephyr ext2 file system validates the on-disk superblock in ext2_verify_disk_superblock() (subsys/fs/ext2/ext2_impl.c) before completing a mount. The validator checked the magic number, block size, revision …

Jul 24, 2026
CVE-2026-66007
6.5 MEDIUM

Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadata field is not properly validated …

Jul 24, 2026
CVE-2026-66006
5.3 MEDIUM

lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint that allows unauthenticated attackers to overwrite operator metadata including …

Jul 24, 2026
CVE-2026-66005
6.3 MEDIUM

Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host …

Jul 24, 2026
CVE-2026-66004
5.3 MEDIUM

BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitrary files by injecting traversal sequences in …

Jul 24, 2026
CVE-2026-49326
6.5 MEDIUM

Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest service has 3 steps, open, fetch(possible multiple times), close. …

Jul 24, 2026
CVE-2026-17059
6.5 MEDIUM

A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. …

Jul 24, 2026
CVE-2026-16802
6.5 MEDIUM

Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to …

Jul 24, 2026
CVE-2026-16799
5.0 MEDIUM

Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader …

Jul 24, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.