CVE Database

47974+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-58387
7.5 HIGH

Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying …

Sep 30, 2026
CVE-2023-54403
7.5 HIGH

Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 …

Sep 30, 2026
CVE-2023-54402
7.5 HIGH

iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers to fetch arbitrary URLs by supplying a hardcoded default …

Sep 30, 2026
CVE-2026-102994
7.5 HIGH

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifiers or generation-number tokens that continue for a …

Sep 30, 2026
CVE-2026-102993
7.5 HIGH

pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py …

Sep 30, 2026
CVE-2026-101885
7.8 HIGH

ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers …

Sep 30, 2026
CVE-2026-101884
7.5 HIGH

OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or …

Sep 30, 2026
CVE-2026-101882
8.8 HIGH

OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. …

Sep 30, 2026
CVE-2026-101880
8.8 HIGH

OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or …

Sep 30, 2026
CVE-2026-97291
8.8 HIGH

Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions.

Sep 30, 2026
CVE-2026-97290
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions.

Sep 30, 2026
CVE-2026-97256
7.2 HIGH

Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions.

Sep 30, 2026
CVE-2026-94171
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme CURCY woo-multi-currency allows DOM-Based XSS.This issue affects CURCY: 2.2.18.

Sep 30, 2026
CVE-2026-87004
8.1 HIGH

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token …

Sep 30, 2026
CVE-2026-53605
7.8 HIGH

Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. …

Sep 30, 2026
CVE-2026-103474
8.8 HIGH

yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role …

Sep 30, 2026
CVE-2026-103473
8.1 HIGH

Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers …

Sep 30, 2026
CVE-2026-103472
7.5 HIGH

restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream …

Sep 30, 2026
CVE-2026-103471
7.5 HIGH

restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory. Attackers can open TCP …

Sep 30, 2026
CVE-2026-102392
7.2 HIGH

Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions.

Sep 30, 2026
CVE-2026-102391
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions.

Sep 30, 2026
CVE-2026-102377
8.8 HIGH

Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions.

Sep 30, 2026
CVE-2026-102376
7.1 HIGH

Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions.

Sep 30, 2026
CVE-2026-100510
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions.

Sep 30, 2026
CVE-2026-46711
8.3 HIGH

Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 …

Sep 30, 2026
CVE-2026-103232
7.3 HIGH

A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/table_booking.php. This manipulation of the argument …

Sep 30, 2026
CVE-2026-47602
7.1 HIGH

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user can cause the driver to …

Sep 30, 2026
CVE-2026-47601
7.8 HIGH

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module DMA-BUF import path where an unprivileged local user could …

Sep 30, 2026
CVE-2026-47600
7.8 HIGH

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an error-handling path could operate on an improperly …

Sep 30, 2026
CVE-2026-47599
7.8 HIGH

NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module where an unprivileged local user could cause improper preservation of memory …

Sep 30, 2026
CVE-2026-47598
7.0 HIGH

NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module event delivery path where an unprivileged local user could cause a …

Sep 30, 2026
CVE-2026-47597
7.8 HIGH

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module Resource Server where an unprivileged local user could cause …

Sep 30, 2026
CVE-2026-47596
7.0 HIGH

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can write to read-only memory because the …

Sep 30, 2026
CVE-2026-47595
7.8 HIGH

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can write to read-only memory because the …

Sep 30, 2026
CVE-2026-47594
7.8 HIGH

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by issuing a sequence of …

Sep 30, 2026
CVE-2026-47593
7.8 HIGH

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an unprivileged user can cause an out-of-bounds write. A successful …

Sep 30, 2026
CVE-2026-47592
7.8 HIGH

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause an out-of-bounds read. …

Sep 30, 2026
CVE-2026-47591
7.8 HIGH

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could bypass read-only memory protection due to …

Sep 30, 2026
CVE-2026-47590
7.8 HIGH

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by issuing a sequence of …

Sep 30, 2026
CVE-2026-47589
7.8 HIGH

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by issuing a sequence of …

Sep 30, 2026
CVE-2026-47588
7.8 HIGH

NVIDIA GPU Display Driver for Linux contains a vulnerability where an unprivileged user could cause a use-after-free condition by issuing a sequence of driver commands. …

Sep 30, 2026
CVE-2026-47587
7.8 HIGH

NVIDIA GPU Display Driver for Linux contains a vulnerability where an unprivileged user could cause a use-after-free. A successful exploit of this vulnerability might lead …

Sep 30, 2026
CVE-2026-47585
7.8 HIGH

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause an integer underflow. A successful exploit of …

Sep 30, 2026
CVE-2026-47583
7.8 HIGH

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause type confusion. A successful exploit of this …

Sep 30, 2026
CVE-2026-47582
7.0 HIGH

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause an out-of-bounds write. A successful exploit of …

Sep 30, 2026
CVE-2026-47580
7.3 HIGH

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause a missing authorization issue. A successful exploit …

Sep 30, 2026
CVE-2026-47579
7.8 HIGH

The NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode driver through which a user might trigger a use-after-free condition. Successful …

Sep 30, 2026
CVE-2026-47578
7.8 HIGH

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an attacker could cause an incorrect buffer size calculation. A …

Sep 30, 2026
CVE-2026-47577
7.8 HIGH

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause an incorrect comparison. A successful exploit of …

Sep 30, 2026
CVE-2026-47576
7.7 HIGH

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module through which an attacker might initiate an out-of-bounds read. Successful exploitation of …

Sep 30, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.