CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-13072
8.1 HIGH

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory …

Jul 22, 2026
CVE-2026-13059
8.1 HIGH

An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to …

Jul 22, 2026
CVE-2026-64835
8.8 HIGH

FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds …

Jul 22, 2026
CVE-2026-64834
7.5 HIGH

FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service …

Jul 22, 2026
CVE-2026-64833
7.1 HIGH

FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying …

Jul 22, 2026
CVE-2026-64832
8.8 HIGH

FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by …

Jul 22, 2026
CVE-2026-16157
7.8 HIGH

Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. Installing the software outside of the Program Files directory, or on …

Jul 22, 2026
CVE-2026-65013
8.8 HIGH

Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources …

Jul 22, 2026
CVE-2026-64831
8.8 HIGH

FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses …

Jul 22, 2026
CVE-2026-64830
8.8 HIGH

FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by …

Jul 22, 2026
CVE-2026-49499
8.8 HIGH

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote …

Jul 22, 2026
CVE-2026-40714
7.2 HIGH

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attacker with remote access could potentially exploit this …

Jul 22, 2026
CVE-2026-16607
7.8 HIGH

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for local privilege escalation to root of an …

Jul 22, 2026
CVE-2026-48029
7.1 HIGH

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate …

Jul 22, 2026
CVE-2026-14985
7.8 HIGH

The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper …

Jul 22, 2026
CVE-2026-13321
8.6 HIGH

The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 …

Jul 22, 2026
CVE-2026-13204
7.5 HIGH

If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one …

Jul 22, 2026
CVE-2026-12617
7.5 HIGH

The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if …

Jul 22, 2026
CVE-2026-11721
7.5 HIGH

It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone …

Jul 22, 2026
CVE-2026-11622
7.5 HIGH

A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to …

Jul 22, 2026
CVE-2026-11605
7.5 HIGH

The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not …

Jul 22, 2026
CVE-2026-11331
7.5 HIGH

An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG …

Jul 22, 2026
CVE-2026-62145
7.5 HIGH

A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.

Jul 22, 2026
CVE-2026-55973
7.5 HIGH

In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream …

Jul 22, 2026
CVE-2026-44690
7.5 HIGH

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive …

Jul 22, 2026
CVE-2026-40691
7.5 HIGH

In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails …

Jul 22, 2026
CVE-2026-32665
7.5 HIGH

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC …

Jul 22, 2026
CVE-2026-13190
8.1 HIGH

In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which …

Jul 22, 2026
CVE-2026-13189
7.5 HIGH

In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to …

Jul 22, 2026
CVE-2026-13187
8.1 HIGH

In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processing and enabling chained exploitation.

Jul 22, 2026
CVE-2026-13186
8.1 HIGH

In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage …

Jul 22, 2026
CVE-2026-13185
8.1 HIGH

In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code …

Jul 22, 2026
CVE-2026-13184
7.5 HIGH

In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall …

Jul 22, 2026
CVE-2026-13183
7.5 HIGH

In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to …

Jul 22, 2026
CVE-2026-13182
7.5 HIGH

In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals …

Jul 22, 2026
CVE-2026-13181
8.1 HIGH

In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code …

Jul 22, 2026
CVE-2026-44191
7.8 HIGH

A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and …

Jul 22, 2026
CVE-2026-65603
8.8 HIGH

The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile self-update handler (processUserProfile(), the update_user task). Unlike the …

Jul 22, 2026
CVE-2026-65598
7.5 HIGH

n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authenticated users to bypass path restrictions …

Jul 22, 2026
CVE-2026-65596
8.1 HIGH

n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic Auth, Query Auth, OAuth) …

Jul 22, 2026
CVE-2026-65595
8.8 HIGH

n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardless of the acting user's role. …

Jul 22, 2026
CVE-2026-65591
8.8 HIGH

n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow create or modify permissions can craft a …

Jul 22, 2026
CVE-2026-65016
8.8 HIGH

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. The provisioning path maps an IdP-asserted role claim …

Jul 22, 2026
CVE-2026-65015
8.8 HIGH

n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer …

Jul 22, 2026
CVE-2026-61391
7.2 HIGH

There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets.

Jul 22, 2026
CVE-2026-61390
7.7 HIGH

There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.

Jul 22, 2026
CVE-2026-57600
7.5 HIGH

Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.

Jul 22, 2026
CVE-2026-4773
8.1 HIGH

Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authentication Bypass. This issue affects IDM-MFA: from 2025.11.27 before 2026.03.10.

Jul 22, 2026
CVE-2026-44190
7.8 HIGH

A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands …

Jul 22, 2026
CVE-2026-44189
7.8 HIGH

A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook …

Jul 22, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.