CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-32821
8.1 HIGH

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, …

Jul 20, 2026
CVE-2026-32820
7.5 HIGH

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, …

Jul 20, 2026
CVE-2026-32819
4.3 MEDIUM

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, …

Jul 20, 2026
CVE-2026-32806
7.5 HIGH

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, …

Jul 20, 2026
CVE-2026-16312

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 20, 2026
CVE-2026-6793
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT Poll allows Stored XSS. This issue affects …

Jul 20, 2026
CVE-2026-63429
8.6 HIGH

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` requirement, …

Jul 20, 2026
CVE-2026-63428
5.8 MEDIUM

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id, name, value}]` array from the submitter and stores it verbatim …

Jul 20, 2026
CVE-2026-63102
5.4 MEDIUM

rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role …

Jul 20, 2026
CVE-2026-51027
9.9 CRITICAL

An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.

Jul 20, 2026
CVE-2026-51026
6.5 MEDIUM

Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a crafted request.

Jul 20, 2026
CVE-2026-48824
5.3 MEDIUM

Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2026-45710, "Mailpit: Set a default 50MB p/m …

Jul 20, 2026
CVE-2026-46671
4.4 MEDIUM

Rust OneNote File Parser is a parser for Microsoft OneNote files implemented in Rust. Prior to version 1.1.1, a maliciously crafted `.onetoc2` table-of-contents file can …

Jul 20, 2026
CVE-2026-46428

lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in lettre's `boring-tls` integration silently …

Jul 20, 2026
CVE-2026-46415
8.2 HIGH

The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's IP address. Prior to …

Jul 20, 2026
CVE-2026-46412
10.0 CRITICAL

@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used …

Jul 20, 2026
CVE-2026-45797

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, the `/api/upload` endpoint allows unauthenticated file uploads including SVG files. Uploaded SVGs are stored in …

Jul 20, 2026
CVE-2026-45713
7.5 HIGH

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that controls …

Jul 20, 2026
CVE-2026-45712
5.9 MEDIUM

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?data=…) maintains a package-level assets map[string]MessageAssets cache, but …

Jul 20, 2026
CVE-2026-45711
5.9 MEDIUM

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <out-dir> sub-command downloads every message from …

Jul 20, 2026
CVE-2026-45709
5.8 MEDIUM

Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side Request Forgery (SSRF) via HTML Check API"), shipped in …

Jul 20, 2026
CVE-2026-35198
9.0 CRITICAL

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member …

Jul 20, 2026
CVE-2026-32822
6.1 MEDIUM

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, …

Jul 20, 2026
CVE-2026-32807
7.5 HIGH

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, …

Jul 20, 2026
CVE-2026-28220
8.4 HIGH

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API …

Jul 20, 2026
CVE-2026-27823

A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute arbitrary commands …

Jul 20, 2026
CVE-2026-26199

HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is invoked on a group id with …

Jul 20, 2026
CVE-2026-26197

HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If a file is corrupted such that an array …

Jul 20, 2026
CVE-2026-26081
4.8 MEDIUM

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

Jul 20, 2026
CVE-2026-26080
3.7 LOW

HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.

Jul 20, 2026
CVE-2026-25039
8.8 HIGH

Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanitize the workspace name, creating a vulnerability if that …

Jul 20, 2026
CVE-2026-21824
8.8 HIGH

HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

Jul 20, 2026
CVE-2026-13724
4.3 MEDIUM

Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System allows Input Data Manipulation. This …

Jul 20, 2026
CVE-2026-63091
6.5 MEDIUM

ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass …

Jul 20, 2026
CVE-2026-63090
8.8 HIGH

ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution …

Jul 20, 2026
CVE-2026-63071
9.8 CRITICAL

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing …

Jul 20, 2026
CVE-2026-62418
8.1 HIGH

Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from …

Jul 20, 2026
CVE-2026-62183
9.8 CRITICAL

Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user workflow adapter is configured, …

Jul 20, 2026
CVE-2026-59238

Stored Cross-site Scripting (CWE-79) in the client-side report rendering functions (renderPreview, renderEditor, renderAuditData in js/app.js) in maalfer Pentestify before 1.1.0 allows a remote, authenticated attacker …

Jul 20, 2026
CVE-2026-57308
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of …

Jul 20, 2026
CVE-2026-54910
7.7 HIGH

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and …

Jul 20, 2026
CVE-2026-54685
5.3 MEDIUM

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` authentication endpoint does not execute in constant time. When a …

Jul 20, 2026
CVE-2026-53421
9.8 CRITICAL

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on …

Jul 20, 2026
CVE-2026-53405
9.8 CRITICAL

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then …

Jul 20, 2026
CVE-2026-52349
7.8 HIGH

Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local attacker to execute arbitrary code via the Spooner …

Jul 20, 2026
CVE-2026-51386

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2026-46409. Reason: This record is a reservation duplicate of CVE-2026-46409. Notes: All CVE users should reference …

Jul 20, 2026
CVE-2026-46516

Frogman provides headless FreePBX control. Prior to version 1.6.6, Frogman's chat-console markdown formatter (`assets/js/chat.js`'s `formatMarkdown`) inserted regex capture groups as raw HTML in four template …

Jul 20, 2026
CVE-2026-46410

FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may leak some sensitive info, such as source and path. …

Jul 20, 2026
CVE-2026-45270
8.7 HIGH

CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` validation rule on language-keyed page …

Jul 20, 2026
CVE-2026-45139
6.5 MEDIUM

CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (`['css','js','html','txt','json','sql','md']`) on content-write operations (`saveFile`, …

Jul 20, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.