CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-63136
6.5 MEDIUM

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially …

Jul 21, 2026
CVE-2026-63092
4.3 MEDIUM

kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any authenticated Kirby Panel user to retrieve the full plaintext commercial …

Jul 21, 2026
CVE-2026-63080
6.5 MEDIUM

Aptabase through commit 5a89368 contains a SQL injection vulnerability in the ClickHouse query backend that allows authenticated attackers to read event data across all tenants …

Jul 21, 2026
CVE-2026-56147
7.1 HIGH

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity compromise via Privilege Abuse (CAPEC-122). An inconsistency …

Jul 21, 2026
CVE-2026-52476
7.5 HIGH

SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the getPageData method in the DatacenterQuery.java file

Jul 21, 2026
CVE-2026-52475
6.1 MEDIUM

Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the UploadController.java file

Jul 21, 2026
CVE-2026-52474
7.5 HIGH

An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUtil.java file.

Jul 21, 2026
CVE-2026-52472
9.8 CRITICAL

SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml file

Jul 21, 2026
CVE-2026-52470
9.8 CRITICAL

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml file

Jul 21, 2026
CVE-2026-52469
9.8 CRITICAL

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml file

Jul 21, 2026
CVE-2026-47714
6.1 MEDIUM

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code in `libheif/region.cc` contains an …

Jul 21, 2026
CVE-2026-47708

MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` parameter in the `stata_do` API and …

Jul 21, 2026
CVE-2026-47697
7.1 HIGH

Shelf is a platform for tracking physical assets. Shelf is multi-tenant; data is isolated per organization (workspace). Prior to version 1.20.2, several endpoints accepted entity …

Jul 21, 2026
CVE-2026-47695

CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to version 1.119.0, CC-Tweaked's HTTP API (`http.request`, …

Jul 21, 2026
CVE-2026-47690
7.5 HIGH

MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to commit 923820de8f64d753951fbbd54f7282a3d5f75173 were vulnerable to exfiltration …

Jul 21, 2026
CVE-2026-47689
4.6 MEDIUM

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `buildRow()` method in `fogpage.class.php` substitutes data values into HTML …

Jul 21, 2026
CVE-2026-47688
8.2 HIGH

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked …

Jul 21, 2026
CVE-2026-47687
7.3 HIGH

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `selectForm()` helper in `fogpage.class.php` renders `<option>` labels using raw, …

Jul 21, 2026
CVE-2026-47685
7.3 HIGH

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the unauthenticated inventory service endpoint (`/service/inventory.php`) persists client-supplied values without …

Jul 21, 2026
CVE-2026-47237
8.0 HIGH

Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests …

Jul 21, 2026
CVE-2026-47143
5.1 MEDIUM

Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F …

Jul 21, 2026
CVE-2026-46556
6.5 MEDIUM

FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Request Forgery (SSRF) vulnerability in get_image_info() …

Jul 21, 2026
CVE-2026-45383

libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a heap buffer overflow (out-of-bounds READ) exists in `decoder_context::decode_slice_unit_WPP()` …

Jul 21, 2026
CVE-2026-45382

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, `decoder_context::decode_slice_unit_tiles` (libde265/decctx.cc:920) reads `pps.CtbAddrRStoTS[ctbAddrRS]` at line 966 where `ctbAddrRS = …

Jul 21, 2026
CVE-2026-44879
7.2 HIGH

A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote attacker to perform command injection on certain CLI …

Jul 21, 2026
CVE-2026-44878
7.2 HIGH

A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the device's filesystem. Successful …

Jul 21, 2026
CVE-2026-30633
7.5 HIGH

Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools.

Jul 21, 2026
CVE-2026-30631
9.8 CRITICAL

An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute arbitrary code via crafted path to `computer_write_file`.

Jul 21, 2026
CVE-2026-16318
5.3 MEDIUM

The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store the peer's transport parameters. When a TLS 1.3 connection …

Jul 21, 2026
CVE-2026-16317
6.5 MEDIUM

Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently discard individual application data records …

Jul 21, 2026
CVE-2026-12139
4.4 MEDIUM

Tanium addressed an information disclosure vulnerability in Connect.

Jul 21, 2026
CVE-2026-11925
2.7 LOW

Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server.

Jul 21, 2026
CVE-2026-65069
4.0 MEDIUM

Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in dsu.h …

Jul 21, 2026
CVE-2026-65068
3.8 LOW

Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sphash.h …

Jul 21, 2026
CVE-2026-65067
3.8 LOW

Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in intern.h …

Jul 21, 2026
CVE-2026-65066
3.8 LOW

Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ring.h …

Jul 21, 2026
CVE-2026-65065
5.5 MEDIUM

Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in roaring.h …

Jul 21, 2026
CVE-2026-65064
3.8 LOW

Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in shm_generic.h …

Jul 21, 2026
CVE-2026-65063
3.8 LOW

Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in radix.h …

Jul 21, 2026
CVE-2026-65062
3.8 LOW

Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sortedset.h …

Jul 21, 2026
CVE-2026-65061
3.8 LOW

Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in reqrep.h …

Jul 21, 2026
CVE-2026-64880
7.1 HIGH

Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized …

Jul 21, 2026
CVE-2026-64879
9.9 CRITICAL

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and …

Jul 21, 2026
CVE-2026-64878
9.9 CRITICAL

Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via …

Jul 21, 2026
CVE-2026-64617
3.8 LOW

Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in pubsub.h …

Jul 21, 2026
CVE-2026-64616

Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ndarray.h …

Jul 21, 2026
CVE-2026-64615
3.3 LOW

Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in graph.h …

Jul 21, 2026
CVE-2026-64614
3.8 LOW

Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in deque.h …

Jul 21, 2026
CVE-2026-64613
6.2 MEDIUM

Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOLLOW. The segment is created in buf_generic.h with open(path, …

Jul 21, 2026
CVE-2026-59147
9.8 CRITICAL

Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find. The attach-time validator dsu_validate_header checks the header …

Jul 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.