CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-35365
6.6 MEDIUM

The mv utility in uutils coreutils improperly handles directory trees containing symbolic links during moves across filesystem boundaries. Instead of preserving symlinks, the implementation expands …

Apr 22, 2026
CVE-2026-35364
6.3 MEDIUM

A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mv utility of uutils coreutils during cross-device operations. The utility removes the destination path before …

Apr 22, 2026
CVE-2026-35363
5.6 MEDIUM

A vulnerability in the rm utility of uutils coreutils allows the bypass of safeguard mechanisms intended to protect the current directory. While the utility correctly …

Apr 22, 2026
CVE-2026-35360
6.3 MEDIUM

The touch utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file creation. When the utility identifies a missing …

Apr 22, 2026
CVE-2026-35359
4.7 MEDIUM

A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the cp utility of uutils coreutils allows an attacker to bypass no-dereference intent. The utility checks if a …

Apr 22, 2026
CVE-2026-35358
4.4 MEDIUM

The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats character and block device nodes as stream sources rather than preserving them. …

Apr 22, 2026
CVE-2026-35357
4.7 MEDIUM

The cp utility in uutils coreutils is vulnerable to an information disclosure race condition. Destination files are initially created with umask-derived permissions (e.g., 0644) before …

Apr 22, 2026
CVE-2026-35356
6.3 MEDIUM

A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the install utility of uutils coreutils when using the -D flag. The command creates parent directories and …

Apr 22, 2026
CVE-2026-35355
6.3 MEDIUM

The install utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during file installation. The implementation unlinks an existing destination …

Apr 22, 2026
CVE-2026-35354
4.7 MEDIUM

A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the mv utility of uutils coreutils during cross-device moves. The extended attribute (xattr) preservation logic uses multiple …

Apr 22, 2026
CVE-2026-35351
4.2 MEDIUM

The mv utility in uutils coreutils fails to preserve file ownership during moves across different filesystem boundaries. The utility falls back to a copy-and-delete routine …

Apr 22, 2026
CVE-2026-35350
6.6 MEDIUM

The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, …

Apr 22, 2026
CVE-2026-35349
6.7 MEDIUM

A vulnerability in the rm utility of uutils coreutils allows a bypass of the --preserve-root protection. The implementation uses a path-string check rather than comparing …

Apr 22, 2026
CVE-2026-35348
5.5 MEDIUM

The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs containing non-UTF-8 filenames. The implementation enforces …

Apr 22, 2026
CVE-2026-35347
4.4 MEDIUM

The comm utility in uutils coreutils incorrectly consumes data from non-regular file inputs before performing comparison operations. The are_files_identical function opens and reads from both …

Apr 22, 2026
CVE-2026-35345
5.3 MEDIUM

A vulnerability in the tail utility of uutils coreutils allows for the exfiltration of sensitive file contents when using the --follow=name option. Unlike GNU tail, …

Apr 22, 2026
CVE-2026-35340
5.5 MEDIUM

A flaw in the ChownExecutor used by uutils coreutils chown and chgrp causes the utilities to return an incorrect exit code during recursive operations. The …

Apr 22, 2026
CVE-2026-35339
5.5 MEDIUM

The recursive mode (-R) of the chmod utility in uutils coreutils incorrectly handles exit codes when processing multiple files. The final return value is determined …

Apr 22, 2026
CVE-2026-32885
6.5 MEDIUM

DDEV is an open-source tool for running local web development environments for PHP and Node.js. Versions prior to 1.25.2 have unsanitized extraction in both `Untar()` …

Apr 22, 2026
CVE-2026-1660
6.5 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain …

Apr 22, 2026
CVE-2025-6016
6.5 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have …

Apr 22, 2026
CVE-2025-3922
6.5 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have …

Apr 22, 2026
CVE-2025-0186
6.5 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have …

Apr 22, 2026
CVE-2026-30139
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the AdvancedSearch functionality of Silverpeas Core before version 6.4.6 allows attackers to execute arbitrary JavaScript in the context …

Apr 22, 2026
CVE-2025-58922
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada allows Cross Site Request Forgery.This issue affects Avada: from n/a before 7.13.2.

Apr 22, 2026
CVE-2024-58344
6.4 MEDIUM

Carbon Forum 5.9.0 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript code through the Forum Name field in dashboard …

Apr 22, 2026
CVE-2018-25271
6.2 MEDIUM

Textpad 8.1.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long buffer string through the …

Apr 22, 2026
CVE-2018-25269
6.1 MEDIUM

ICEWARP 11.0.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML elements into emails by embedding base64-encoded payloads in object and embed …

Apr 22, 2026
CVE-2018-25267
6.2 MEDIUM

UltraISO 9.7.1.3519 contains a local buffer overflow vulnerability in the Output FileName field of the Make CD/DVD Image dialog that allows attackers to overwrite SEH …

Apr 22, 2026
CVE-2018-25266
6.2 MEDIUM

Angry IP Scanner 3.5.3 contains a buffer overflow vulnerability in the preferences dialog that allows local attackers to crash the application by supplying an excessively …

Apr 22, 2026
CVE-2018-25262
6.2 MEDIUM

Angry IP Scanner for Linux 3.5.3 contains a denial of service vulnerability that allows local attackers to crash the application by supplying malformed input to …

Apr 22, 2026
CVE-2026-6862
5.5 MEDIUM

A flaw was found in libefiboot, a component of efivar. The device path node parser in libefiboot fails to validate that each node's Length field …

Apr 22, 2026
CVE-2026-6861
6.1 MEDIUM

A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading …

Apr 22, 2026
CVE-2026-6355
6.5 MEDIUM

A vulnerability in the web application allows unauthorized users to access and manipulate sensitive data across different tenants by exploiting insecure direct object references. This …

Apr 22, 2026
CVE-2026-33611
6.5 MEDIUM

An operator allowed to use the REST API can cause the Authoritative server to produce invalid HTTPS or SVCB record data, which can in turn …

Apr 22, 2026
CVE-2026-33610
5.9 MEDIUM

A rogue primary server may cause file descriptor exhaustion and eventually a denial of service, when a PowerDNS secondary server forwards a DNS update request …

Apr 22, 2026
CVE-2026-33609
5.3 MEDIUM

Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform queries of internal domain subtrees.

Apr 22, 2026
CVE-2026-33602
6.5 MEDIUM

A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds …

Apr 22, 2026
CVE-2026-33598
4.8 MEDIUM

A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet cache.

Apr 22, 2026
CVE-2026-33595
5.3 MEDIUM

A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 connection, as some resources were …

Apr 22, 2026
CVE-2026-33594
5.3 MEDIUM

A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accumulate …

Apr 22, 2026
CVE-2026-33254
5.3 MEDIUM

An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial of …

Apr 22, 2026
CVE-2026-31529
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fix leakage in __construct_region() Failing the first sysfs_update_group() needs to explicitly kfree the resource …

Apr 22, 2026
CVE-2026-31526
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix exception exit lock checking for subprogs process_bpf_exit_full() passes check_lock = !curframe to check_resource_leak(), …

Apr 22, 2026
CVE-2026-31524
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: asus: avoid memory leak in asus_report_fixup() The asus_report_fixup() function was returning a newly allocated …

Apr 22, 2026
CVE-2026-31523
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvme-pci: ensure we're polling a polled queue A user can change the polled queue count …

Apr 22, 2026
CVE-2026-31522
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: magicmouse: avoid memory leak in magicmouse_report_fixup() The magicmouse_report_fixup() function was returning a newly kmemdup()-allocated …

Apr 22, 2026
CVE-2026-31521
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: module: Fix kernel panic when a symbol st_shndx is out of bounds The module loader …

Apr 22, 2026
CVE-2026-31520
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: apple: avoid memory leak in apple_report_fixup() The apple_report_fixup() function was returning a newly kmemdup()-allocated …

Apr 22, 2026
CVE-2026-31519
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create We have recently observed a number of subvolumes with …

Apr 22, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.