CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-43797
5.5 MEDIUM

This issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6. An app may be able …

Jul 27, 2026
CVE-2026-43796
5.5 MEDIUM

This issue was addressed with improved data protection. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS …

Jul 27, 2026
CVE-2026-43792
6.5 MEDIUM

An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.6. An app may be able to …

Jul 27, 2026
CVE-2026-43782
5.5 MEDIUM

This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be …

Jul 27, 2026
CVE-2026-43781
4.7 MEDIUM

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app …

Jul 27, 2026
CVE-2026-43775
5.5 MEDIUM

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able …

Jul 27, 2026
CVE-2026-43774
5.5 MEDIUM

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app …

Jul 27, 2026
CVE-2026-43770
4.7 MEDIUM

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6. An …

Jul 27, 2026
CVE-2026-43768
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may …

Jul 27, 2026
CVE-2026-43767
5.0 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may …

Jul 27, 2026
CVE-2026-43766
4.6 MEDIUM

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker …

Jul 27, 2026
CVE-2026-43765
5.5 MEDIUM

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app …

Jul 27, 2026
CVE-2026-43763
5.5 MEDIUM

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An …

Jul 27, 2026
CVE-2026-43759
5.5 MEDIUM

An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.6, watchOS 26.6. An app may be able to …

Jul 27, 2026
CVE-2026-43758
5.5 MEDIUM

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. …

Jul 27, 2026
CVE-2026-43756
5.5 MEDIUM

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may …

Jul 27, 2026
CVE-2026-43754
5.5 MEDIUM

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An …

Jul 27, 2026
CVE-2026-43753
4.6 MEDIUM

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, …

Jul 27, 2026
CVE-2026-43744
5.5 MEDIUM

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma …

Jul 27, 2026
CVE-2026-43739
5.5 MEDIUM

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, …

Jul 27, 2026
CVE-2026-43738
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted asset catalog …

Jul 27, 2026
CVE-2026-43714
5.5 MEDIUM

The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS …

Jul 27, 2026
CVE-2026-43665
5.5 MEDIUM

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A local attacker may be able …

Jul 27, 2026
CVE-2026-28932
5.5 MEDIUM

A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma …

Jul 27, 2026
CVE-2026-28900
5.5 MEDIUM

A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive …

Jul 27, 2026
CVE-2026-28849
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass …

Jul 27, 2026
CVE-2026-20672
5.5 MEDIUM

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be …

Jul 27, 2026
CVE-2026-66018
6.5 MEDIUM

Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving …

Jul 27, 2026
CVE-2026-65925
6.5 MEDIUM

A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.

Jul 27, 2026
CVE-2026-65924
6.5 MEDIUM

JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access …

Jul 27, 2026
CVE-2026-65923
6.8 MEDIUM

A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The …

Jul 27, 2026
CVE-2026-65618
6.5 MEDIUM

Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and …

Jul 27, 2026
CVE-2026-64649
6.5 MEDIUM

Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or …

Jul 27, 2026
CVE-2026-64648
5.4 MEDIUM

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request …

Jul 27, 2026
CVE-2026-66757
5.5 MEDIUM

A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The …

Jul 27, 2026
CVE-2026-66031
5.4 MEDIUM

Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by …

Jul 27, 2026
CVE-2026-64647
5.4 MEDIUM

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request …

Jul 27, 2026
CVE-2026-64646
5.3 MEDIUM

Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, requests targeting Next.js applications using App …

Jul 27, 2026
CVE-2026-10682
6.6 MEDIUM

The userspace verifier z_vrfy_log_filter_set() for the log_filter_set syscall in subsys/logging/log_mgmt.c performed a signed comparison against the int16_t src_id parameter: src_id < (int16_t)log_src_cnt_get(domain_id). Any negative value …

Jul 27, 2026
CVE-2026-66030
5.4 MEDIUM

Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by …

Jul 27, 2026
CVE-2026-66029
5.4 MEDIUM

Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by …

Jul 27, 2026
CVE-2026-66028
6.7 MEDIUM

Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email …

Jul 27, 2026
CVE-2026-64645
6.1 MEDIUM

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that …

Jul 27, 2026
CVE-2026-64644
5.3 MEDIUM

Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, when self-hosting Next.js with the default …

Jul 27, 2026
CVE-2026-64643
5.3 MEDIUM

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server …

Jul 27, 2026
CVE-2026-48052
5.4 MEDIUM

Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who is a member of any organization can delete …

Jul 27, 2026
CVE-2026-17570
4.3 MEDIUM

Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API …

Jul 27, 2026
CVE-2026-17569
4.3 MEDIUM

Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API …

Jul 27, 2026
CVE-2026-66391
6.5 MEDIUM

Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. …

Jul 27, 2026
CVE-2026-66390
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 …

Jul 27, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.