CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-41362
4.3 MEDIUM

OpenClaw versions 2026.2.19 before 2026.3.31 contain an improper cache isolation vulnerability in the Zalo webhook replay-dedupe mechanism that is shared across authenticated webhook targets. Attackers …

Apr 28, 2026
CVE-2026-40977
4.7 MEDIUM

When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the …

Apr 28, 2026
CVE-2026-40975
4.8 MEDIUM

Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as …

Apr 28, 2026
CVE-2026-40974
5.0 MEDIUM

Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), …

Apr 28, 2026
CVE-2026-7183
5.3 MEDIUM

A vulnerability has been found in aligungr UERANSIM up to 3.2.7. The affected element is the function rls::DecodeRlsMessage in the library src/lib/rls/rls_pdu.cpp of the component …

Apr 27, 2026
CVE-2026-7179
5.3 MEDIUM

A security vulnerability has been detected in OSPG binwalk up to 2.4.3. This vulnerability affects the function read_null_terminated_string of the file src/binwalk/plugins/winceextract.py of the component …

Apr 27, 2026
CVE-2026-40971
5.0 MEDIUM

When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. Affected: Spring Boot …

Apr 27, 2026
CVE-2026-29971
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in WebFileSys version before 2.32.0 and fixed in v.2.32.0. User-controlled input is reflected into HTML and JavaScript contexts …

Apr 27, 2026
CVE-2026-7150
6.3 MEDIUM

A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the function generate_favicon_from_url of the file src/auto_favicon/server.py of the component MCP Tool. …

Apr 27, 2026
CVE-2026-7148
6.3 MEDIUM

A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Executing a manipulation of the argument …

Apr 27, 2026
CVE-2026-40970
5.0 MEDIUM

When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server. Affected: Spring Boot …

Apr 27, 2026
CVE-2026-35902
6.2 MEDIUM

The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with …

Apr 27, 2026
CVE-2026-35901
4.4 MEDIUM

A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attacker to trigger session termination by repeatedly …

Apr 27, 2026
CVE-2026-32655
5.3 MEDIUM

Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with local access could potentially exploit …

Apr 27, 2026
CVE-2021-36438
6.5 MEDIUM

SQL Injection vulnerability exists in Sourcecodester Online Job Portal phppdo 1.0 ivia the category parameter in /jobportal/index.php.

Apr 27, 2026
CVE-2026-7145
5.4 MEDIUM

A weakness has been identified in mettle sendportal up to 3.0.1. Affected is the function destroy of the file app/Http/Controllers/Workspaces/WorkspaceInvitationsController.php of the component Invitation Handler. …

Apr 27, 2026
CVE-2026-7144
4.3 MEDIUM

A security flaw has been discovered in 1000 Projects Portfolio Management System MCA 1.0. This impacts an unknown function of the file update_passwd_process.php. The manipulation …

Apr 27, 2026
CVE-2026-7143
6.3 MEDIUM

A vulnerability was identified in 1000 Projects Portfolio Management System MCA up to 1.0. This affects an unknown function of the file /admin/block_status.php. The manipulation …

Apr 27, 2026
CVE-2026-31691
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: igb: remove napi_synchronize() in igb_down() When an AF_XDP zero-copy application terminates abruptly (e.g., kill -9), …

Apr 27, 2026
CVE-2026-31689
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: EDAC/mc: Fix error path ordering in edac_mc_alloc() When the mci->pvt_info allocation in edac_mc_alloc() fails, the …

Apr 27, 2026
CVE-2026-31687
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gpio: omap: do not register driver in probe() Commit 11a78b794496 ("ARM: OMAP: MPUIO wake updates") …

Apr 27, 2026
CVE-2026-25908
6.7 MEDIUM

Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain an Execution with Unnecessary Privileges vulnerability in the AWCC. A low privileged attacker with local …

Apr 27, 2026
CVE-2026-7142
6.3 MEDIUM

A vulnerability was determined in Wooey up to 0.13.2. The impacted element is the function add_or_update_script of the file wooey/api/scripts.py of the component API Endpoint. …

Apr 27, 2026
CVE-2026-7141
5.6 MEDIUM

A vulnerability was found in vllm up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v1/kv_cache_interface.py of the component KV Block …

Apr 27, 2026
CVE-2026-38936
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/selectindices.php via the namecontains parameter

Apr 27, 2026
CVE-2026-38935
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/view.php via the doctype parameter

Apr 27, 2026
CVE-2026-30462
4.3 MEDIUM

A path traversal vulnerability in the Blocks module of Daylight Studio FuelCMS v1.5.2 allows attackers to execute a directory traversal.

Apr 27, 2026
CVE-2026-30346
4.3 MEDIUM

An open redirect in the /api/google/authorize endpoint of hunvreus DevPush v0.3.2 allows attackers to redirect users to malicious sites via supplying a crafted URL.

Apr 27, 2026
CVE-2026-7135
5.3 MEDIUM

A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is the function elng_box_read of the file src/isomedia/box_code_base.c of the …

Apr 27, 2026
CVE-2026-7134
4.7 MEDIUM

A vulnerability was identified in code-projects Online Lot Reservation System 1.0. Affected is an unknown function of the file /edithousepic.php. Such manipulation of the argument …

Apr 27, 2026
CVE-2026-41467
5.4 MEDIUM

ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the file upload functionality where the checkValidFileName() function fails to restrict HTML and …

Apr 27, 2026
CVE-2026-41466
5.4 MEDIUM

ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the checkValidHtmlText() function within Security.php that fails to properly sanitize user input by …

Apr 27, 2026
CVE-2026-41465
6.5 MEDIUM

ProjeQtor versions 7.0 through 12.4.3 contains a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against …

Apr 27, 2026
CVE-2026-41464
6.5 MEDIUM

ProjeQtor versions 7.0 through 12.4.3 contain a missing authorization vulnerability in the objectDetail.php endpoint that allows authenticated users with guest-level privileges to retrieve sensitive data …

Apr 27, 2026
CVE-2026-7133
4.7 MEDIUM

A vulnerability was determined in code-projects Online Lot Reservation System 1.0. This impacts an unknown function of the file /activity.php. This manipulation of the argument …

Apr 27, 2026
CVE-2026-7132
5.3 MEDIUM

A vulnerability was found in code-projects Online Lot Reservation System up to 1.0. This affects the function readfile of the file /download.php. The manipulation of …

Apr 27, 2026
CVE-2026-40514
5.9 MEDIUM

SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints that use DES-CBC encryption with keys and initialization …

Apr 27, 2026
CVE-2026-7129
4.3 MEDIUM

A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the file /index.php?page=categories. Performing a manipulation of …

Apr 27, 2026
CVE-2026-41081
6.5 MEDIUM

Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Description: When TLS transport is …

Apr 27, 2026
CVE-2026-40557
4.8 MEDIUM

Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter Versions Affected: from 2.6.3 to 2.8.6 Description: In production deployments where an …

Apr 27, 2026
CVE-2026-7118
6.3 MEDIUM

A security vulnerability has been detected in code-projects Employee Management System 1.0. The affected element is an unknown function of the file 370project/cancel.php. The manipulation …

Apr 27, 2026
CVE-2026-7117
6.3 MEDIUM

A weakness has been identified in code-projects Employee Management System 1.0. Impacted is an unknown function of the file 370project/approve.php. Executing a manipulation of the …

Apr 27, 2026
CVE-2026-7116
4.3 MEDIUM

A security flaw has been discovered in code-projects Employee Management System 1.0. This issue affects some unknown processing of the file 370project/mark.php. Performing a manipulation …

Apr 27, 2026
CVE-2026-5942
5.5 MEDIUM

Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to access invalidated objects and crash the program.

Apr 27, 2026
CVE-2026-5939
5.5 MEDIUM

A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution.

Apr 27, 2026
CVE-2026-5938
5.5 MEDIUM

Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial …

Apr 27, 2026
CVE-2026-5937
5.5 MEDIUM

Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "std::invalid_argument" exception, ultimately causing the program to terminate.

Apr 27, 2026
CVE-2026-42410
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows DOM-Based XSS.This issue affects TheGem Theme …

Apr 27, 2026
CVE-2026-7115
6.3 MEDIUM

A vulnerability was identified in code-projects Employee Management System 1.0. This vulnerability affects unknown code of the file 370project/delete.php. Such manipulation of the argument ID …

Apr 27, 2026
CVE-2026-7114
6.3 MEDIUM

A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown part of the file 370project/edit.php. This manipulation of the argument ID …

Apr 27, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.