CVE Database

60653+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-44584
4.3 MEDIUM

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the email update functionality fails to invalidate …

Jul 20, 2026
CVE-2026-44583
5.3 MEDIUM

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the PayPal webhook endpoint /extensions/paypal/webhook processes the …

Jul 20, 2026
CVE-2026-44509
6.3 MEDIUM

Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, previous bug fixes for …

Jul 20, 2026
CVE-2026-44507
4.8 MEDIUM

Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, when using a daemon …

Jul 20, 2026
CVE-2026-53592
4.6 MEDIUM

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in the `getQueryParam` function `/public/js/main.js` and was …

Jul 20, 2026
CVE-2026-44230
6.1 MEDIUM

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not …

Jul 20, 2026
CVE-2026-44229
5.4 MEDIUM

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a …

Jul 20, 2026
CVE-2026-63768
4.3 MEDIUM

cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows attackers to redirect users to arbitrary URLs by crafting …

Jul 20, 2026
CVE-2026-63730
5.0 MEDIUM

HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to make requests to arbitrary internal network …

Jul 20, 2026
CVE-2026-61901
6.1 MEDIUM

Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an open redirect.

Jul 20, 2026
CVE-2026-55639
5.3 MEDIUM

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Security Data within the Client MCS …

Jul 20, 2026
CVE-2026-45295
6.5 MEDIUM

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tracking endpoint `GET /thread/read/{conversation_id}/{thread_id}` allows …

Jul 20, 2026
CVE-2026-44228
5.4 MEDIUM

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Scripting (XSS) vulnerability, …

Jul 20, 2026
CVE-2026-44227
6.1 MEDIUM

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. …

Jul 20, 2026
CVE-2026-26483
6.1 MEDIUM

Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management functionality. The application fails to properly sanitize user-supplied input …

Jul 20, 2026
CVE-2026-58482
5.9 MEDIUM

Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalInbox` (`lib/approval-inbox.ts`). It is the network surface of the human-in-the-loop Approval Gate, which …

Jul 20, 2026
CVE-2026-58481
6.5 MEDIUM

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped file access under a configured sandbox `basePath`, but its path containment checks …

Jul 20, 2026
CVE-2026-58414
5.5 MEDIUM

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using `_collectBackupFiles()`. `_collectBackupFiles()` uses `statSync(full)`, which follows symlinks. If `data/<env>` contains …

Jul 20, 2026
CVE-2026-58413
6.1 MEDIUM

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, backupId)` computes the backup path with `join(envDir, '.backups', backupId)` and only checks that this …

Jul 20, 2026
CVE-2026-55645
6.5 MEDIUM

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of Client Control PDUs. During the RDP connection …

Jul 20, 2026
CVE-2026-55238
5.3 MEDIUM

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Confirm Active PDU, where during the …

Jul 20, 2026
CVE-2026-50743
5.4 MEDIUM

A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted …

Jul 20, 2026
CVE-2026-47276
6.5 MEDIUM

In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `properties_parse()` allows an authenticated attacker to crash the NanoMQ broker by sending a POST …

Jul 20, 2026
CVE-2026-44978
5.3 MEDIUM

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap out-of-bounds read vulnerability within the FIPS-specific receive paths. This vulnerability does …

Jul 20, 2026
CVE-2026-42218
5.3 MEDIUM

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login interface. Due to a discrepancy in …

Jul 20, 2026
CVE-2026-35217
6.5 MEDIUM

NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` handling: if a subscription entry is missing the final 1-byte `Subscription Options` field, the broker …

Jul 20, 2026
CVE-2026-32823
4.3 MEDIUM

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, …

Jul 20, 2026
CVE-2026-32819
4.3 MEDIUM

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, …

Jul 20, 2026
CVE-2026-6793
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT Poll allows Stored XSS. This issue affects …

Jul 20, 2026
CVE-2026-63428
5.8 MEDIUM

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id, name, value}]` array from the submitter and stores it verbatim …

Jul 20, 2026
CVE-2026-63102
5.4 MEDIUM

rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role …

Jul 20, 2026
CVE-2026-51026
6.5 MEDIUM

Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a crafted request.

Jul 20, 2026
CVE-2026-48824
5.3 MEDIUM

Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2026-45710, "Mailpit: Set a default 50MB p/m …

Jul 20, 2026
CVE-2026-46671
4.4 MEDIUM

Rust OneNote File Parser is a parser for Microsoft OneNote files implemented in Rust. Prior to version 1.1.1, a maliciously crafted `.onetoc2` table-of-contents file can …

Jul 20, 2026
CVE-2026-45712
5.9 MEDIUM

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?data=…) maintains a package-level assets map[string]MessageAssets cache, but …

Jul 20, 2026
CVE-2026-45711
5.9 MEDIUM

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <out-dir> sub-command downloads every message from …

Jul 20, 2026
CVE-2026-45709
5.8 MEDIUM

Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side Request Forgery (SSRF) via HTML Check API"), shipped in …

Jul 20, 2026
CVE-2026-32822
6.1 MEDIUM

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, …

Jul 20, 2026
CVE-2026-26081
4.8 MEDIUM

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

Jul 20, 2026
CVE-2026-13724
4.3 MEDIUM

Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System allows Input Data Manipulation. This …

Jul 20, 2026
CVE-2026-63091
6.5 MEDIUM

ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass …

Jul 20, 2026
CVE-2026-54685
5.3 MEDIUM

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` authentication endpoint does not execute in constant time. When a …

Jul 20, 2026
CVE-2026-45139
6.5 MEDIUM

CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (`['css','js','html','txt','json','sql','md']`) on content-write operations (`saveFile`, …

Jul 20, 2026
CVE-2026-16277
6.5 MEDIUM

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information returned by the server …

Jul 20, 2026
CVE-2026-16244
6.3 MEDIUM

A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /prescriptionorderreport.php. Such …

Jul 20, 2026
CVE-2026-63762
6.5 MEDIUM

SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript scripting engine, which is enabled via the --allow-scripting capability …

Jul 20, 2026
CVE-2026-63761
4.3 MEDIUM

SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with ALGORITHM ES512 (DEFINE ACCESS ... TYPE JWT ALGORITHM ES512), …

Jul 20, 2026
CVE-2026-63759
6.5 MEDIUM

SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annotations. Authenticated attackers can send queries with deeply …

Jul 20, 2026
CVE-2026-63758
5.4 MEDIUM

SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenticated database users to terminate other users' LIVE SELECT subscriptions. …

Jul 20, 2026
CVE-2026-63755
6.5 MEDIUM

SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH clauses in UPDATE, UPSERT, INSERT ON DUPLICATE KEY UPDATE, and RELATE update-variant statements) …

Jul 20, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.