CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-59146
7.8 HIGH

Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sph_walk_cell and sph_alloc_slot. The attach-time validator …

Jul 21, 2026
CVE-2026-59145
9.1 CRITICAL

Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find. The attach-time validator si_validate_header is thorough …

Jul 21, 2026
CVE-2026-59144
9.8 CRITICAL

Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time validator ring_validate_header checks the capacity-overflow and …

Jul 21, 2026
CVE-2026-59143
6.3 MEDIUM

Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offset and cardinality in rb_contains_locked. The attach-time validator rb_validate_header checks the …

Jul 21, 2026
CVE-2026-56852
7.5 HIGH

A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

Jul 21, 2026
CVE-2026-56146
5.4 MEDIUM

Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with …

Jul 21, 2026
CVE-2026-56145
6.5 MEDIUM

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL …

Jul 21, 2026
CVE-2026-56144
5.3 MEDIUM

Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By …

Jul 21, 2026
CVE-2026-50759
7.5 HIGH

An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instance/{instance_id} endpoints with no authentication.

Jul 21, 2026
CVE-2026-50758
8.1 HIGH

Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter

Jul 21, 2026
CVE-2026-50757
7.8 HIGH

Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server

Jul 21, 2026
CVE-2026-50756
7.5 HIGH

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component

Jul 21, 2026
CVE-2026-50755
9.8 CRITICAL

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value

Jul 21, 2026
CVE-2026-49092
4.3 MEDIUM

Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under …

Jul 21, 2026
CVE-2026-47671
5.4 MEDIUM

Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost configserver` used by `nhost dev` …

Jul 21, 2026
CVE-2026-47667
7.5 HIGH

CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field is read as an `unsigned int` from …

Jul 21, 2026
CVE-2026-46600
7.5 HIGH

Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

Jul 21, 2026
CVE-2026-46403
6.3 MEDIUM

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithTypedArguments` as a read-only execution mechanism. The hook saves the …

Jul 21, 2026
CVE-2026-42397
6.5 MEDIUM

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can …

Jul 21, 2026
CVE-2026-30632
7.5 HIGH

Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool.

Jul 21, 2026
CVE-2026-15957
7.5 HIGH

Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust …

Jul 21, 2026
CVE-2026-64877
8.4 HIGH

An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.

Jul 21, 2026
CVE-2026-63454
7.2 HIGH

An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location …

Jul 21, 2026
CVE-2026-63453
7.2 HIGH

Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execute arbitrary …

Jul 21, 2026
CVE-2026-59142
9.1 CRITICAL

Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy. The attach-time validator shm_validate_header checks the …

Jul 21, 2026
CVE-2026-59141
9.1 CRITICAL

Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked. The attach-time validator rdx_validate_header checks the header …

Jul 21, 2026
CVE-2026-59140
9.1 CRITICAL

Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths. The attach-time validator ss_validate_header …

Jul 21, 2026
CVE-2026-59139
9.1 CRITICAL

Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked. The attach-time validator reqrep_validate_header checks the …

Jul 21, 2026
CVE-2026-55084
8.8 HIGH

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL injection vulnerability was identified in the SqlView API endpoint …

Jul 21, 2026
CVE-2026-55082

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. DHIS2 SQL View data endpoints allowed authenticated users with SQL View …

Jul 21, 2026
CVE-2026-55081

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. The DHIS2 OpenAPI HTML endpoint reflected values from the `scope` query …

Jul 21, 2026
CVE-2026-16441

In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, execution is incorrectly …

Jul 21, 2026
CVE-2026-12548
4.2 MEDIUM

A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause …

Jul 21, 2026
CVE-2026-12547
3.4 LOW

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached …

Jul 21, 2026
CVE-2016-20096
9.8 CRITICAL

Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the …

Jul 21, 2026
CVE-2026-56583
3.1 LOW

HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijacking, and account misuse.

Jul 21, 2026
CVE-2026-56582
3.1 LOW

HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sensitive information through a TLS/SSL padding oracle attack.

Jul 21, 2026
CVE-2026-56581
2.6 LOW

HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens.

Jul 21, 2026
CVE-2026-56580
2.2 LOW

HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit publicly disclosed weaknesses and compromise …

Jul 21, 2026
CVE-2026-56579
3.1 LOW

HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed information and compromise the application's security.

Jul 21, 2026
CVE-2026-56578
2.2 LOW

HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities affecting the disclosed software versions.

Jul 21, 2026
CVE-2026-56577
3.1 LOW

HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks.

Jul 21, 2026
CVE-2026-47657

HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in the Space member management controller allowed any …

Jul 21, 2026
CVE-2026-47425

Rattler is a library that provides common functionality used within the conda ecosystem. Prior to version 0.43.2, `EntryPoint::FromStr` in `rattler_conda_types` performs only `.trim()` on the …

Jul 21, 2026
CVE-2026-47419
8.3 HIGH

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an* Insecure Direct Object Reference. The agent CRUD …

Jul 21, 2026
CVE-2026-47418
8.1 HIGH

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The project CRUD …

Jul 21, 2026
CVE-2026-47417
8.1 HIGH

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The comment endpoints …

Jul 21, 2026
CVE-2026-47416
9.6 CRITICAL

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/members/{user_id}` …

Jul 21, 2026
CVE-2026-47415
8.3 HIGH

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The issue CRUD …

Jul 21, 2026
CVE-2026-47414
7.6 HIGH

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. Five label endpoints …

Jul 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.