CVE Database

60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-102141
6.7 MEDIUM

Two Kiteworks Core cluster-management operations did not validate file paths supplied to them, so an attacker holding root on one node of a cluster could …

Sep 30, 2026
CVE-2026-102140
4.9 MEDIUM

An authenticated administrator could initiate an administrative import using a file whose contents were not fully verified, because the import validated only the file's header …

Sep 30, 2026
CVE-2026-102139
6.5 MEDIUM

An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party …

Sep 30, 2026
CVE-2026-102137
4.1 MEDIUM

An authenticated administrator could bypass the content validation applied to an administrative file upload and store a file containing dangerous content on the appliance. This …

Sep 30, 2026
CVE-2026-102136
6.3 MEDIUM

In multi-node deployments, an attacker who had already obtained code execution on one appliance node could submit a value through an internal cluster interface that …

Sep 30, 2026
CVE-2026-102135
6.6 MEDIUM

On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted serialized object that was …

Sep 30, 2026
CVE-2026-102134
5.4 MEDIUM

Kiteworks Core did not apply its gateway-level API security controls to every request authenticated through the platform's central authentication service. An authenticated user could reach …

Sep 30, 2026
CVE-2026-102133
6.6 MEDIUM

An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. …

Sep 30, 2026
CVE-2026-102124
6.5 MEDIUM

A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration. An unauthenticated attacker with network access to the appliance …

Sep 30, 2026
CVE-2026-102122
4.3 MEDIUM

Kiteworks did not correctly enforce which roles a shared folder's manager was permitted to assign. In a default configuration, an authenticated user holding the Manager …

Sep 30, 2026
CVE-2026-102111
4.9 MEDIUM

Kiteworks did not enforce the maximum permitted value for a configurable security-policy setting. An authenticated administrator could set this value outside its intended range so …

Sep 30, 2026
CVE-2026-102110
5.9 MEDIUM

An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so during the initial activation …

Sep 30, 2026
CVE-2026-102107
4.6 MEDIUM

Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authenticated user to send a request that appeared to originate from …

Sep 30, 2026
CVE-2026-102090
4.3 MEDIUM

Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to …

Sep 30, 2026
CVE-2026-103387
4.3 MEDIUM

A weakness has been identified in garycourt uri-js up to 4.4.1. This affects the function URI.parse of the file src/schemes/mailto.ts of the component Mailto Header …

Sep 30, 2026
CVE-2026-102991
6.5 MEDIUM

Mako is a template library written in Python. Prior to 1.4.2, on Windows, TemplateLookup.get_template() in mako/lookup.py resolves template URIs with posixpath, while Template.__init__() in mako/template.py …

Sep 30, 2026
CVE-2026-101883
5.4 MEDIUM

OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers with …

Sep 30, 2026
CVE-2026-101881
6.5 MEDIUM

OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node …

Sep 30, 2026
CVE-2026-101879
6.5 MEDIUM

OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that allows connected gateways or agents to perform screen snapshots, camera …

Sep 30, 2026
CVE-2026-97265
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a …

Sep 30, 2026
CVE-2026-103476
5.3 MEDIUM

yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers can enumerate …

Sep 30, 2026
CVE-2026-103399
5.3 MEDIUM

A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an …

Sep 30, 2026
CVE-2026-102397
6.5 MEDIUM

Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions.

Sep 30, 2026
CVE-2026-102375
6.5 MEDIUM

Subscriber Broken Access Control in Optimole <= 4.2.14 versions.

Sep 30, 2026
CVE-2026-103241
5.3 MEDIUM

A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file rust/src/parser/src/unified/gemma4.rs of the component Gemma4UnifiedParser. Executing …

Sep 30, 2026
CVE-2026-103233
6.3 MEDIUM

A security vulnerability has been detected in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This impacts an unknown function of the file /admin/ of the component Admin …

Sep 30, 2026
CVE-2026-55174
5.9 MEDIUM

UltrafastSecp256k1 is a high-performance, multi-backend secp256k1 engine with reproducible audit evidence, compatibility shims, and profile-based review scopes. Prior to version 4.2.0, UltrafastSecp256k1's ECDSA adaptor pre-signature …

Sep 30, 2026
CVE-2026-47604
5.5 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user may access another process's GPU …

Sep 30, 2026
CVE-2026-47603
5.5 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user may access another process's GPU …

Sep 30, 2026
CVE-2026-47586
6.4 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel module where an attacker could cause a use-after-free. A successful exploit …

Sep 30, 2026
CVE-2026-47584
5.5 MEDIUM

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker with local access could cause a NULL pointer dereference. …

Sep 30, 2026
CVE-2026-47581
5.5 MEDIUM

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where a user could cause improper locking. A successful exploit of this …

Sep 30, 2026
CVE-2026-47568
5.5 MEDIUM

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause uncontrolled kernel log generation by repeatedly …

Sep 30, 2026
CVE-2026-47567
5.5 MEDIUM

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where a user could cause uncontrolled resource consumption by exhausting the …

Sep 30, 2026
CVE-2026-47566
5.5 MEDIUM

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a memory leak in error …

Sep 30, 2026
CVE-2026-47565
6.4 MEDIUM

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a privileged user could trigger a race condition that leads …

Sep 30, 2026
CVE-2026-47562
4.4 MEDIUM

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could inject crafted text into the kernel log …

Sep 30, 2026
CVE-2026-47557
5.5 MEDIUM

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a NULL pointer dereference. A …

Sep 30, 2026
CVE-2026-47555
5.5 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where a user could cause uninitialized kernel memory to …

Sep 30, 2026
CVE-2026-47549
5.5 MEDIUM

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel module where an unprivileged local user could cause a NULL pointer dereference. A …

Sep 30, 2026
CVE-2026-47547
6.7 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause improper input validation. A successful exploit …

Sep 30, 2026
CVE-2026-47546
6.7 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause improper input validation. A successful exploit …

Sep 30, 2026
CVE-2026-47544
6.7 MEDIUM

NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful …

Sep 30, 2026
CVE-2026-47543
6.7 MEDIUM

VIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause improper input validation. A …

Sep 30, 2026
CVE-2026-47542
6.7 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause improper input validation. A …

Sep 30, 2026
CVE-2026-47539
6.7 MEDIUM

NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an incorrect numeric conversion. A …

Sep 30, 2026
CVE-2026-47538
6.7 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds write. A successful exploit …

Sep 30, 2026
CVE-2026-47537
6.7 MEDIUM

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit …

Sep 30, 2026
CVE-2026-47534
5.5 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause a divide by zero. …

Sep 30, 2026
CVE-2026-47533
6.7 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an improper validation of …

Sep 30, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.