CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-12705
6.4 MEDIUM

Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE). This issue affects KNX Update Tool (ABB): through …

Jul 17, 2026
CVE-2026-9592

SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, …

Jul 17, 2026
CVE-2026-7488
7.5 HIGH

Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data. This issue affects E-Commerce: through 03062026.

Jul 17, 2026
CVE-2026-51080
9.8 CRITICAL

libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.

Jul 17, 2026
CVE-2026-16072
4.9 MEDIUM

A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a …

Jul 17, 2026
CVE-2026-16016
7.3 HIGH

A vulnerability was identified in poco-ai poco-claw up to 0.5.4. This issue affects the function run_task of the file executor/app/api/v1/task.py. The manipulation of the argument …

Jul 17, 2026
CVE-2026-16015
6.3 MEDIUM

A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of the file executor_manager/app/api/v1/tasks.py of the component executor_manager API. …

Jul 17, 2026
CVE-2025-60357
8.1 HIGH

AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEvent/list endpoint.

Jul 17, 2026
CVE-2024-42214
5.3 MEDIUM

HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the …

Jul 17, 2026
CVE-2024-23578
4.2 MEDIUM

HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from …

Jul 17, 2026
CVE-2024-23577
4.3 MEDIUM

HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requested in http protocol. …

Jul 17, 2026
CVE-2024-23575
5.3 MEDIUM

HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker …

Jul 17, 2026
CVE-2024-23574
5.3 MEDIUM

HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid …

Jul 17, 2026
CVE-2024-23573
3.7 LOW

HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 …

Jul 17, 2026
CVE-2024-23572
4.2 MEDIUM

HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You …

Jul 17, 2026
CVE-2024-23571
4.3 MEDIUM

HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and …

Jul 17, 2026
CVE-2024-23570
4.3 MEDIUM

HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on …

Jul 17, 2026
CVE-2024-23569
4.3 MEDIUM

HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header

Jul 17, 2026
CVE-2024-23568
5.3 MEDIUM

HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information …

Jul 17, 2026
CVE-2024-23567
4.3 MEDIUM

HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during …

Jul 17, 2026
CVE-2024-23566
6.5 MEDIUM

HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force …

Jul 17, 2026
CVE-2024-23565
5.3 MEDIUM

HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor …

Jul 17, 2026
CVE-2024-23564
9.1 CRITICAL

HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and …

Jul 17, 2026
CVE-2026-8396
7.5 HIGH

Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Data External Linking. This issue affects NetGIS: from 5.0.66 before …

Jul 17, 2026
CVE-2026-7189
7.5 HIGH

Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue …

Jul 17, 2026
CVE-2026-16014
7.3 HIGH

A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the component Login Form. Performing a manipulation of …

Jul 17, 2026
CVE-2026-13410
8.2 HIGH

Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An attacker with network man-in-the-middle …

Jul 17, 2026
CVE-2026-13082
5.3 MEDIUM

GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets. The random method creates the challenge text used for the CAPTCHA by sampling characters …

Jul 17, 2026
CVE-2026-16013
5.3 MEDIUM

A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. Affected by this issue is the function CipAppPath::deserialize_symbolic of the file source/src/cip/cipepath.cc. Such manipulation …

Jul 17, 2026
CVE-2026-16009
6.3 MEDIUM

A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /prescriptionorderdetail.php. The manipulation of the argument delid …

Jul 17, 2026
CVE-2026-15943
5.5 MEDIUM

A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an …

Jul 17, 2026
CVE-2026-9602
6.5 MEDIUM

Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious …

Jul 17, 2026
CVE-2026-8075
6.5 MEDIUM

Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user …

Jul 17, 2026
CVE-2026-59695

Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single request by …

Jul 17, 2026
CVE-2026-59694

Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per payment by a …

Jul 17, 2026
CVE-2026-59252

Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet, resulting in denial of service …

Jul 17, 2026
CVE-2026-16008
6.3 MEDIUM

A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parsePropertyDependencies of the file src/keywords/propertyDependencies.ts. The manipulation leads to improperly controlled …

Jul 17, 2026
CVE-2026-22104

Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read all cracked hashes of …

Jul 17, 2026
CVE-2026-62764

Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user without system permissions may issue a remote command to gracefully shutdown …

Jul 17, 2026
CVE-2026-9656
4.3 MEDIUM

The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Jul 17, 2026
CVE-2026-15380

A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS …

Jul 17, 2026
CVE-2026-15379

The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the SYSTEM …

Jul 17, 2026
CVE-2026-9810
9.8 CRITICAL

The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator …

Jul 17, 2026
CVE-2026-13402
5.3 MEDIUM

The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one …

Jul 17, 2026
CVE-2026-12393
5.4 MEDIUM

The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling it, allowing …

Jul 17, 2026
CVE-2026-11966
5.3 MEDIUM

The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticated callers on one of its membership payment actions …

Jul 17, 2026
CVE-2026-11961
8.1 HIGH

The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers …

Jul 17, 2026
CVE-2026-11575
7.5 HIGH

The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback …

Jul 17, 2026
CVE-2026-10525
6.1 MEDIUM

The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and outputting it back in the admin …

Jul 17, 2026
CVE-2019-25764

**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and …

Jul 17, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.