CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-28312
9.1 CRITICAL

SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The …

Jul 21, 2026
CVE-2026-28310
9.1 CRITICAL

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. …

Jul 21, 2026
CVE-2026-28309
9.1 CRITICAL

SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in …

Jul 21, 2026
CVE-2026-28308
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The …

Jul 21, 2026
CVE-2026-28307
9.1 CRITICAL

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is …

Jul 21, 2026
CVE-2026-28306
9.1 CRITICAL

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is …

Jul 21, 2026
CVE-2026-28305
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with …

Jul 21, 2026
CVE-2026-28304
9.1 CRITICAL

SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact …

Jul 21, 2026
CVE-2026-28302
9.1 CRITICAL

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This …

Jul 21, 2026
CVE-2026-16450
4.3 MEDIUM

A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the function getTenantId of the file /api/system/sys/dept/page of the component MyBatis-Plus Tenant Plugin. …

Jul 21, 2026
CVE-2026-16449
6.3 MEDIUM

A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The impacted element is the function OrderItem.asc/OrderItem.desc of the file /api/system/sys/dept/page of the component com.zs.sys.dept.controller.SysDeptController. …

Jul 21, 2026
CVE-2026-8933
7.8 HIGH

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap …

Jul 21, 2026
CVE-2026-65052
7.5 HIGH

Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form …

Jul 21, 2026
CVE-2026-65051
6.5 MEDIUM

Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging …

Jul 21, 2026
CVE-2026-65050
6.5 MEDIUM

Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated …

Jul 21, 2026
CVE-2026-65049
9.3 CRITICAL

Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of …

Jul 21, 2026
CVE-2026-65048
9.3 CRITICAL

Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary …

Jul 21, 2026
CVE-2026-59851
8.8 HIGH

A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for …

Jul 21, 2026
CVE-2026-59850
4.3 MEDIUM

A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated …

Jul 21, 2026
CVE-2026-59849
3.1 LOW

A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are …

Jul 21, 2026
CVE-2026-56587
3.7 LOW

HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications.

Jul 21, 2026
CVE-2026-56584
3.7 LOW

HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly …

Jul 21, 2026
CVE-2026-47122
4.2 MEDIUM

Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `shouldAcceptNewConnection:` only enforces `SUCodeSigningVerifier validateConnection:` before stage 1 completes. …

Jul 21, 2026
CVE-2026-46681

@nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility library. Prior to version 0.14.0, the _copyProps function in lib/src/object/copy.ts uses for...in to iterate over source object properties without …

Jul 21, 2026
CVE-2026-16448
6.3 MEDIUM

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 …

Jul 21, 2026
CVE-2026-15226
8.4 HIGH

A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default seccomp security templates generated by the engine …

Jul 21, 2026
CVE-2026-11876
5.0 MEDIUM

In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/stack` endpoint (`get_deployed_stack`) lacks proper RBAC authorization checks, allowing any authenticated user to enumerate all deployed stacks across all …

Jul 21, 2026
CVE-2024-5300
5.6 MEDIUM

An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd …

Jul 21, 2026
CVE-2026-9499

An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NUL-terminated (for example, …

Jul 21, 2026
CVE-2026-59848
5.3 MEDIUM

A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded …

Jul 21, 2026
CVE-2026-59847
5.9 MEDIUM

A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker …

Jul 21, 2026
CVE-2026-47121
6.1 MEDIUM

Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `relativePath.pathComponents containsObject:@".."` and rejects writes whose immediate parent directory IS itself …

Jul 21, 2026
CVE-2026-16447
7.3 HIGH

A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument Filedata[] leads …

Jul 21, 2026
CVE-2025-66390
9.8 CRITICAL

In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the registration flow …

Jul 21, 2026
CVE-2026-8285
4.3 MEDIUM

Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. FlexCity allows Excessive Allocation. This issue affects FlexCity: from 5.536.0 through 11052026.

Jul 21, 2026
CVE-2026-8284
6.1 MEDIUM

URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data Manipulation. This issue affects FlexCity: from 5.536.0 through 11052026.

Jul 21, 2026
CVE-2026-6792
6.5 MEDIUM

Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCity: from 5.536.0 through 11052026.

Jul 21, 2026
CVE-2026-59846
3.9 LOW

A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended …

Jul 21, 2026
CVE-2026-16445
7.5 HIGH

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as …

Jul 21, 2026
CVE-2026-16412
9.8 CRITICAL

Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with …

Jul 21, 2026
CVE-2026-16411
9.8 CRITICAL

Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of …

Jul 21, 2026
CVE-2026-16410
9.8 CRITICAL

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16409
7.5 HIGH

Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16408
9.8 CRITICAL

Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16407
9.8 CRITICAL

Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16406
9.1 CRITICAL

Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16405
7.5 HIGH

Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Jul 21, 2026
CVE-2026-16404
7.4 HIGH

Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16403
6.5 MEDIUM

Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16402
9.8 CRITICAL

Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.