CVE Database

60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-47532
6.7 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A …

Sep 30, 2026
CVE-2026-47531
4.4 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause a null pointer dereference. …

Sep 30, 2026
CVE-2026-47529
6.7 MEDIUM

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit …

Sep 30, 2026
CVE-2026-47527
6.7 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds read. A successful exploit …

Sep 30, 2026
CVE-2026-47526
4.4 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause a null pointer dereference. A successful …

Sep 30, 2026
CVE-2026-47525
6.7 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an improper validation of …

Sep 30, 2026
CVE-2026-47524
6.7 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A …

Sep 30, 2026
CVE-2026-47522
6.7 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause improper input validation. A …

Sep 30, 2026
CVE-2026-47518
6.0 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a secure microcontroller component, where incorrect permission assignment for a critical resource allows …

Sep 30, 2026
CVE-2026-47517
5.5 MEDIUM

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode driver where a local user may cause a null pointer dereference by …

Sep 30, 2026
CVE-2026-47515
6.7 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds read via …

Sep 30, 2026
CVE-2026-47509
6.7 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds write. A …

Sep 30, 2026
CVE-2026-47506
5.5 MEDIUM

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel-mode color transform path where excessive kernel stack use occurs when evaluating YCbCr420 display …

Sep 30, 2026
CVE-2026-47492
5.5 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an attacker can cause improper access control. A …

Sep 30, 2026
CVE-2026-100279
6.5 MEDIUM

In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials

Sep 30, 2026
CVE-2026-100278
4.9 MEDIUM

In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments

Sep 30, 2026
CVE-2026-100276
5.9 MEDIUM

In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action

Sep 30, 2026
CVE-2026-100275
6.9 MEDIUM

In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible

Sep 30, 2026
CVE-2026-100274
6.5 MEDIUM

In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template

Sep 30, 2026
CVE-2026-100272
4.9 MEDIUM

In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues

Sep 30, 2026
CVE-2026-100269
4.3 MEDIUM

In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed

Sep 30, 2026
CVE-2026-100267
5.9 MEDIUM

In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters

Sep 30, 2026
CVE-2026-100265
4.8 MEDIUM

In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation

Sep 30, 2026
CVE-2026-100263
4.7 MEDIUM

In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible

Sep 30, 2026
CVE-2026-100261
5.4 MEDIUM

In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission

Sep 30, 2026
CVE-2026-100260
5.3 MEDIUM

In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset

Sep 30, 2026
CVE-2026-100259
4.3 MEDIUM

In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access

Sep 30, 2026
CVE-2026-100258
4.3 MEDIUM

In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings

Sep 30, 2026
CVE-2026-100257
4.3 MEDIUM

In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export

Sep 30, 2026
CVE-2026-62084
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS. This issue affects User Submitted …

Sep 30, 2026
CVE-2026-103397
5.6 MEDIUM

OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing unpaired room members to impersonate paired devices by spoofing the RelayMessage From …

Sep 30, 2026
CVE-2026-103396
4.3 MEDIUM

bbs-go through 4.4.6 contains a permission bypass vulnerability in the AdminMiddleware authorization logic where the read-only dashboard.user.view permission rule matches the /api/admin/user/synccount endpoint before the …

Sep 30, 2026
CVE-2026-103243
5.8 MEDIUM

LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal endpoints, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply arbitrary …

Sep 30, 2026
CVE-2026-103227
6.3 MEDIUM

A weakness has been identified in GPAC up to 26.07.0. Affected by this issue is the function gf_dash_resolve_url of the file src/media_tools/dash_client.c of the component …

Sep 30, 2026
CVE-2026-103226
6.3 MEDIUM

A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation …

Sep 30, 2026
CVE-2026-103222
5.6 MEDIUM

A vulnerability was determined in Blosc C-Blosc2 up to 3.3.2. This impacts the function blosclz_decompress of the file blosc/blosclz.c of the component blosclz Decompression. Executing …

Sep 30, 2026
CVE-2026-103118
4.3 MEDIUM

A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG …

Sep 30, 2026
CVE-2026-97302
5.3 MEDIUM

Unauthenticated Sensitive Data Exposure in MPG <= 4.2.3 versions.

Sep 30, 2026
CVE-2026-97301
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Cool Formkit Lite <= 2.7.8 versions.

Sep 30, 2026
CVE-2026-97299
5.4 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions.

Sep 30, 2026
CVE-2026-97298
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions.

Sep 30, 2026
CVE-2026-97292
6.5 MEDIUM

Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions.

Sep 30, 2026
CVE-2026-97288
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions.

Sep 30, 2026
CVE-2026-97286
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Strong Testimonials strong-testimonials allows Stored XSS.This issue affects Strong Testimonials: from …

Sep 30, 2026
CVE-2026-97285
5.4 MEDIUM

Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions.

Sep 30, 2026
CVE-2026-97282
5.3 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions.

Sep 30, 2026
CVE-2026-97279
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Polylang <= 3.8.9 versions.

Sep 30, 2026
CVE-2026-97270
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in CMB2 <= 2.13.0 versions.

Sep 30, 2026
CVE-2026-97267
4.3 MEDIUM

Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions.

Sep 30, 2026
CVE-2026-97266
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12.1 versions.

Sep 30, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.