CVE Database

60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-107210
5.3 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a crafted highly compressed MAT image can …

Oct 7, 2026
CVE-2026-107209
5.9 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, when ImageMagick is built without Cairo support, …

Oct 7, 2026
CVE-2026-107208
5.3 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a crafted XMP profile can reach a …

Oct 7, 2026
CVE-2026-107166
5.3 MEDIUM

A weakness has been identified in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pfcp_xact_local_create of the file src/upf/gtp-path.c of the component GTP-U Receive …

Oct 7, 2026
CVE-2026-106580
4.0 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a missing security-policy check in the CUT …

Oct 7, 2026
CVE-2026-106579
6.2 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can bypass an ImageMagick …

Oct 7, 2026
CVE-2026-106578
5.9 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid …

Oct 7, 2026
CVE-2026-106577
5.3 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, unescaped or untrimmed values can inject code …

Oct 7, 2026
CVE-2026-106576
5.3 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a crafted XMP profile can trigger excessive work while …

Oct 7, 2026
CVE-2026-106575
5.3 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a crafted Magick script can cause an opened file …

Oct 7, 2026
CVE-2026-106574
5.3 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a client connected to the distributed pixel cache server …

Oct 7, 2026
CVE-2026-106573
5.3 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a missing limit check in the MVG …

Oct 7, 2026
CVE-2026-106572
5.3 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a missing recursion-depth check in the CALS …

Oct 7, 2026
CVE-2026-106571
5.1 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 6.9.13-56 and 7.1.2-31, a crafted local call to the GetVirtualPixels …

Oct 7, 2026
CVE-2026-106570
4.3 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, an unauthenticated adjacent-network client can repeatedly connect to the …

Oct 7, 2026
CVE-2026-106569
5.3 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, missing validation and resource checks in the ASE decoder …

Oct 7, 2026
CVE-2026-106568
5.3 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted XMP profile embedded in an …

Oct 7, 2026
CVE-2026-106567
5.9 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an …

Oct 7, 2026
CVE-2026-106566
4.0 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, delegate symlink cleanup does not check the MAGICK_SHRED_PASSES environment …

Oct 7, 2026
CVE-2026-106565
5.9 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed …

Oct 7, 2026
CVE-2026-106564
5.3 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, a crafted EXR image can cause the EXR decoder …

Oct 7, 2026
CVE-2026-62179
6.5 MEDIUM

PraisonAI is a multi-agent teams system. In `praisonai-platform` prior to version 0.1.9, issue dependency deletion can be authorized against the wrong side of a dependency …

Oct 7, 2026
CVE-2026-107174
6.4 MEDIUM

A flaw was found in source-to-image. When unpacking archive files, the application fails to properly sanitize symbolic links pointing to absolute file paths. An attacker …

Oct 7, 2026
CVE-2026-107169
6.2 MEDIUM

A flaw was found in m17n-lib. An attacker could provide specially crafted or truncated UTF-8 input to trigger an unhandled null pointer dereference during text …

Oct 7, 2026
CVE-2026-107167
6.2 MEDIUM

A flaw was found in m17n-lib. A user providing specially crafted text input can trigger a heap use-after-free condition during input-method state transitions. Under specific …

Oct 7, 2026
CVE-2026-107125
6.3 MEDIUM

A flaw has been found in XnView Classic 2.52.5. Impacted is an unknown function of the component FLI File Parser. This manipulation of the argument …

Oct 7, 2026
CVE-2026-106563
5.3 MEDIUM

Backstage is an open framework for building developer portals. Prior to 0.21.8, the @backstage/plugin-kubernetes-backend package is affected by improper entity validation in deprecated kubernetes services …

Oct 7, 2026
CVE-2026-106562
4.3 MEDIUM

Backstage is an open framework for building developer portals. Prior to 2.1.6 in @backstage/plugin-search-backend and 1.8.7 in @backstage/plugin-search-backend-module-elasticsearch, search engine permission filtering could return documents …

Oct 7, 2026
CVE-2026-106561
5.0 MEDIUM

Backstage is an open framework for building developer portals. Prior to 0.21.9, the @backstage/plugin-kubernetes-backend package is affected by sensitive information disclosure in kubernetes resource queries. …

Oct 7, 2026
CVE-2026-106559
6.3 MEDIUM

Backstage is an open framework for building developer portals. Prior to 0.3.25, the @backstage/plugin-scaffolder-backend-module-confluence-to-markdown package is affected by improper input validation in confluence to markdown …

Oct 7, 2026
CVE-2026-106064
6.3 MEDIUM

A heap-based buffer overflow was found in GIMP’s GIF export plug-in. Exporting an image with very large width and height can cause 32-bit overflow when …

Oct 7, 2026
CVE-2026-104074
5.3 MEDIUM

Coturn 4.10.0 contains an uninitialized memory disclosure vulnerability that allows remote unauthenticated attackers to leak stack memory contents by sending a TURN Allocate request without …

Oct 7, 2026
CVE-2025-70519
6.1 MEDIUM

The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data. The lack of sanitization allows …

Oct 7, 2026
CVE-2026-88514
5.5 MEDIUM

An issue in iTerm2 macOS before 3.6.12 allows a local attacker to obtain sensitive information.

Oct 7, 2026
CVE-2026-46571
5.5 MEDIUM

In NTFS-3G before 2026.7.7, a out-of-bounds read exists in ntfs_fix_file_name() in libntfs-3g/reparse.c that allows an attacker to read possibly confidential information in ntfs-3g process memory …

Oct 7, 2026
CVE-2026-46438
6.5 MEDIUM

wger is a free, open-source workout and fitness manager. Prior to version 2.6, an authenticated attacker can inject arbitrary workout log entries into any other …

Oct 7, 2026
CVE-2026-46437
4.8 MEDIUM

wger is a free, open-source workout and fitness manager. Versions prior to 2.6 have a vulnerability in the authentication/session lifecycle of `wger` where bearer-style API …

Oct 7, 2026
CVE-2026-45161
5.4 MEDIUM

wger is a free, open-source workout and fitness manager. Prior to version 2.6, the `trainer_login` view in wger accepts GET requests and executes `django_login()` without …

Oct 7, 2026
CVE-2026-102258
6.1 MEDIUM

Post-authentication Stored Cross-Site Scripting (XSS) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote …

Oct 7, 2026
CVE-2026-42532
5.5 MEDIUM

A path traversal vulnerability exists in the EmailSheet extract_parts functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .eml file can lead to arbitrary …

Oct 7, 2026
CVE-2026-41958
6.5 MEDIUM

A path traversal vulnerability exists in the unzip_http RemoteZipFile extract functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .zip file can lead to …

Oct 7, 2026
CVE-2026-107177
5.9 MEDIUM

Express Gateway through 1.16.11 contains a hardcoded cryptographic key vulnerability that allows attackers with datastore access to decrypt stored OAuth 2.0 token secrets via the …

Oct 7, 2026
CVE-2026-107168
6.2 MEDIUM

A flaw was found in m17n-lib. By providing crafted input containing an invalid UTF-8 character sequence, an attacker can cause the text parsing function to …

Oct 7, 2026
CVE-2026-107162
6.8 MEDIUM

Express Gateway through 1.16.11 contains an authentication bypass vulnerability in the OAuth 2.0 refresh_token grant that fails to validate the token secret or issuing client. …

Oct 7, 2026
CVE-2026-107151
5.9 MEDIUM

Missing authentication has been found in remote-execution task updates in the smart_proxy_dynflow package. The progress and completion callbacks accept a report when the one-time token …

Oct 7, 2026
CVE-2026-105140
4.2 MEDIUM

Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships just revoked in …

Oct 7, 2026
CVE-2026-105139
4.3 MEDIUM

Obot 0.26.0 before 0.26.2 contains an authorization bypass vulnerability that allows authenticated users matching any vMCP profile to reach prompts and resources of ungranted components. …

Oct 7, 2026
CVE-2026-105138
6.5 MEDIUM

Obot 0.12.0 before 0.26.2 contains an insufficiently protected credentials vulnerability that allows authenticated users to read static secrets set on MCP catalog entries by admins …

Oct 7, 2026
CVE-2026-107159
6.5 MEDIUM

MiniUPnPd through 2.3.11 built with --strict contains a divide-by-zero vulnerability in ProcessSSDPData() that allows unauthenticated local network attackers to crash the daemon. Attackers can send …

Oct 7, 2026
CVE-2026-97294
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary …

Oct 7, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.