CVE Database

60653+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-62237
6.5 MEDIUM

Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and function, which are allowlisted in the Twig content …

Jul 17, 2026
CVE-2026-62236
5.4 MEDIUM

grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASecret frontend task, which regenerates and persists a new TOTP secret for the …

Jul 17, 2026
CVE-2026-62235
6.3 MEDIUM

Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that allows authenticated users with only api.access permission to …

Jul 17, 2026
CVE-2026-62225
5.4 MEDIUM

OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch that allows lower-trust callers to execute or persist actions beyond their intended …

Jul 17, 2026
CVE-2026-62224
5.4 MEDIUM

OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust access can perform …

Jul 17, 2026
CVE-2026-62221
5.4 MEDIUM

OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller …

Jul 17, 2026
CVE-2026-62220
5.3 MEDIUM

OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the affected feature …

Jul 17, 2026
CVE-2026-62216
5.0 MEDIUM

OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media …

Jul 17, 2026
CVE-2026-62214
6.5 MEDIUM

OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-trust callers to expose bot tokens and credentials by failing to …

Jul 17, 2026
CVE-2026-62213
6.5 MEDIUM

OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can …

Jul 17, 2026
CVE-2026-62211
5.0 MEDIUM

OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain …

Jul 17, 2026
CVE-2026-62210
6.5 MEDIUM

OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read attacks that exhaust gateway worker resources. Attackers with …

Jul 17, 2026
CVE-2026-62208
6.5 MEDIUM

OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enabled and reachable, a lower-trust caller or configured input …

Jul 17, 2026
CVE-2026-44251
6.5 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t …

Jul 17, 2026
CVE-2026-40106
4.7 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above prior to 4.14.5 contain a heap-based …

Jul 17, 2026
CVE-2026-2594
6.4 MEDIUM

The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.7. This is due to insufficient …

Jul 17, 2026
CVE-2026-33754
6.5 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.9.0 and above, prior to 4.14.5, a remote …

Jul 17, 2026
CVE-2026-33434
4.3 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and above, prior to 4.14.5, a logic …

Jul 17, 2026
CVE-2026-44452
5.9 MEDIUM

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or …

Jul 16, 2026
CVE-2026-44434
5.3 MEDIUM

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit dccf5d4, Quicly was vulnerable to stateless …

Jul 16, 2026
CVE-2026-44433
5.3 MEDIUM

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, an adversarial peer could send …

Jul 16, 2026
CVE-2026-62826
4.6 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jul 16, 2026
CVE-2026-58643
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.

Jul 16, 2026
CVE-2026-14782
4.9 MEDIUM

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up …

Jul 16, 2026
CVE-2026-13713
6.2 MEDIUM

YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack. In the …

Jul 16, 2026
CVE-2026-61378
5.5 MEDIUM

A divide-by-zero vulnerability in the Productivity Suite allows a local attacker to cause a division by zero leading to a system crash.

Jul 16, 2026
CVE-2026-60073
5.9 MEDIUM

An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB device. This can lead …

Jul 16, 2026
CVE-2026-57896
6.1 MEDIUM

An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCTL request. This could …

Jul 16, 2026
CVE-2026-36425
6.5 MEDIUM

An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send process termination …

Jul 16, 2026
CVE-2026-33731
6.5 MEDIUM

WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/AuthorizeNet/webhook.php contains a signature verification bypass that …

Jul 16, 2026
CVE-2026-11889
6.5 MEDIUM

SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation attack that could allow an authorized attacker to …

Jul 16, 2026
CVE-2024-32387
5.7 MEDIUM

An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the community string component.

Jul 16, 2026
CVE-2024-32385
4.3 MEDIUM

An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via a boardID and revisionID components

Jul 16, 2026
CVE-2026-63397
6.4 MEDIUM

remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL schema that is passed to genql to inject arbitrary JavaScript or TypeScript. …

Jul 16, 2026
CVE-2026-62299
5.3 MEDIUM

CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an optional revert flag, and …

Jul 16, 2026
CVE-2026-61718
5.4 MEDIUM

bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb web UI BiscuitMiddleware authorization bypass list included the /cache/ …

Jul 16, 2026
CVE-2026-60140
6.1 MEDIUM

An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCTL request. This can …

Jul 16, 2026
CVE-2026-47089
4.3 MEDIUM

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user could call …

Jul 16, 2026
CVE-2026-47085
4.0 MEDIUM

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a …

Jul 16, 2026
CVE-2026-47084
6.5 MEDIUM

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An authenticated but non-admin user could invoke the …

Jul 16, 2026
CVE-2026-47083
4.3 MEDIUM

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated …

Jul 16, 2026
CVE-2026-47082
5.4 MEDIUM

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-mailbox ACL. A user whose vacation Sieve script …

Jul 16, 2026
CVE-2026-46514
6.5 MEDIUM

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_reset_password in Tools/ResetPassword.php:48-53 returned a plaintext password and fm_add_extension in Tools/AddExtension.php:172 returned …

Jul 16, 2026
CVE-2026-46404
6.8 MEDIUM

BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly restrict access to site local and link local addresses. …

Jul 16, 2026
CVE-2026-46378
6.2 MEDIUM

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the selector lexer matchRegexPattern closure in (*Tokenizer).parseCurRune …

Jul 16, 2026
CVE-2026-46377
6.2 MEDIUM

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the escape sequence handler in (*Tokenizer).parseCurRune in …

Jul 16, 2026
CVE-2026-46338
4.3 MEDIUM

PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.snippets uses a string-prefix containment check in SnippetPreprocessor.get_snippet_path() in …

Jul 16, 2026
CVE-2026-46341
6.1 MEDIUM

The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior …

Jul 16, 2026
CVE-2026-44968
6.3 MEDIUM

dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_command() in src/dbt_mcp/dbt_cli/tools.py appended unsanitized node_selection and resource_type values to the …

Jul 16, 2026
CVE-2026-15945
4.3 MEDIUM

A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated …

Jul 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.