CVE Database

10684+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-63939
9.3 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Compute the correct max length of the in-GHCB scratch area When setting the …

Jul 19, 2026
CVE-2026-63938
9.3 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Check PSC request indices against the actual size of the buffer When processing …

Jul 19, 2026
CVE-2026-63924
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() ipv6_hop_jumbo() calls pskb_trim_rcsum(), which can change skb pointers. …

Jul 19, 2026
CVE-2026-63922
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh after handling HAO option ip6_parse_tlv() caches skb_network_header(skb) in nh while walking …

Jul 19, 2026
CVE-2026-63912
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: restore combined single-frag length gate The ESP out-of-place fast path appends the trailer …

Jul 19, 2026
CVE-2026-63888
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() Two latent bugs in the …

Jul 19, 2026
CVE-2026-63887
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf iscsi_encode_text_output() concatenates "key=value\0" records into login->rsp_buf, an …

Jul 19, 2026
CVE-2026-63886
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length before base64 decode chap_server_compute_hash() allocates client_digest as kzalloc(chap->digest_size) and …

Jul 19, 2026
CVE-2026-63857
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net: airoha: Do not read uninitialized fragment address in airoha_dev_xmit() The transmit loop in airoha_dev_xmit() …

Jul 19, 2026
CVE-2026-63830
9.4 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net: skmsg: preserve sg.copy across SG transforms The sk_msg sg.copy bitmap is part of the …

Jul 19, 2026
CVE-2026-63825
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: gcov: use atomic counter updates to fix concurrent access crashes GCC's GCOV instrumentation can merge …

Jul 19, 2026
CVE-2026-63808
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: exfat: fix potential use-after-free in exfat_find_dir_entry() In exfat_find_dir_entry(), the buffer_head obtained from exfat_get_dentry() is released …

Jul 19, 2026
CVE-2026-63800
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() When hitting the NFS_LAYOUT_RETURN branch in pnfs_update_layout(), the code calls …

Jul 19, 2026
CVE-2026-63795
10.0 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() error path When p9_client_walk() is called with clone set …

Jul 19, 2026
CVE-2026-53399
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure nfs4_alloc_stid() publishes the new stid into cl->cl_stateids via …

Jul 19, 2026
CVE-2026-53398
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfsd4_decode_secinfo_no_name() currently initializes sin_exp after decoding sin_style. If the …

Jul 19, 2026
CVE-2026-53384
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails dw8250_probe() registers the 8250 port via serial8250_register_8250_port() …

Jul 19, 2026
CVE-2026-16117
10.0 CRITICAL

Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for …

Jul 18, 2026
CVE-2026-47865
9.8 CRITICAL

VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by …

Jul 18, 2026
CVE-2026-55518
9.6 CRITICAL

Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in …

Jul 17, 2026
CVE-2026-54159
10.0 CRITICAL

PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected search filters from the request URL, …

Jul 17, 2026
CVE-2026-52348
9.8 CRITICAL

cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.

Jul 17, 2026
CVE-2026-48062
9.8 CRITICAL

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived guessed extension instead of the …

Jul 17, 2026
CVE-2026-13446
9.8 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound …

Jul 17, 2026
CVE-2026-8859
9.9 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the …

Jul 17, 2026
CVE-2026-8635
9.9 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve …

Jul 17, 2026
CVE-2026-8505
9.8 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The …

Jul 17, 2026
CVE-2026-8481
9.9 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied …

Jul 17, 2026
CVE-2026-8476
9.9 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() …

Jul 17, 2026
CVE-2026-63030
9.8 CRITICAL KEV

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query …

Jul 17, 2026
CVE-2026-52199
9.1 CRITICAL

An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component

Jul 17, 2026
CVE-2026-42168
9.1 CRITICAL

django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model. These fields are passed directly to …

Jul 17, 2026
CVE-2026-36669
9.8 CRITICAL

An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) to the web-accessible …

Jul 17, 2026
CVE-2026-15091
9.3 CRITICAL

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web …

Jul 17, 2026
CVE-2025-51677
9.1 CRITICAL

An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can …

Jul 17, 2026
CVE-2026-9135
9.9 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that …

Jul 17, 2026
CVE-2026-9103
9.8 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint …

Jul 17, 2026
CVE-2026-9202
9.8 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created …

Jul 17, 2026
CVE-2026-9198
9.8 CRITICAL KEV

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via …

Jul 17, 2026
CVE-2026-8297
9.8 CRITICAL

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab …

Jul 17, 2026
CVE-2026-54496
9.3 CRITICAL

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base scalar …

Jul 17, 2026
CVE-2026-12694
9.1 CRITICAL

Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 …

Jul 17, 2026
CVE-2026-12693
9.4 CRITICAL

Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video …

Jul 17, 2026
CVE-2026-12692
9.8 CRITICAL

Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

Jul 17, 2026
CVE-2026-60024
9.8 CRITICAL

Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow …

Jul 17, 2026
CVE-2026-51080
9.8 CRITICAL

libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.

Jul 17, 2026
CVE-2024-23564
9.1 CRITICAL

HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and …

Jul 17, 2026
CVE-2026-9810
9.8 CRITICAL

The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator …

Jul 17, 2026
CVE-2026-15982
9.8 CRITICAL

The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up …

Jul 17, 2026
CVE-2026-62241
9.1 CRITICAL

clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET …

Jul 17, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.