CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-14628
5.3 MEDIUM

A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of the file gateway/platforms/base.py of the component Live Webhook Endpoint. …

Jul 4, 2026
CVE-2026-14627
5.6 MEDIUM

A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2. This affects the function DiscordAdapter._is_allowed_user of the file gateway/platforms/discord.py of the component Discord …

Jul 4, 2026
CVE-2025-13475
3.5 LOW

In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific SaaS …

Jul 4, 2026
CVE-2026-53362
KEV

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch …

Jul 4, 2026
CVE-2026-53361

In the Linux kernel, the following vulnerability has been resolved: af_unix: Set gc_in_progress to true in unix_gc(). Igor Ushakov reported that unix_gc() could run with …

Jul 4, 2026
CVE-2026-53360

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use As per the …

Jul 4, 2026
CVE-2026-53359

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix …

Jul 4, 2026
CVE-2026-14626
4.3 MEDIUM

A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. The impacted element is the function AIAgent.run_conversation of the file run_agent.py of the component …

Jul 4, 2026
CVE-2026-14625
6.3 MEDIUM

A security flaw has been discovered in NousResearch hermes-agent up to 0.15.2. The affected element is the function shell.exec of the file tui_gateway/server.py. The manipulation …

Jul 4, 2026
CVE-2026-12196

HestiaCP panel cronjob feature is affected by a broken access control vulnerability. Low privilege users can modify the panel cronjob to execute scripts HestiaCP management …

Jul 4, 2026
CVE-2026-12195

myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary commands as a part of the v_ftp_user parameter when …

Jul 4, 2026
CVE-2026-14624
4.3 MEDIUM

A vulnerability was identified in omec-project amf up to 2.0.2/2.1.1. Impacted is an unknown function of the file /go/src/amf/ngap/handler.go of the component NGSetupRequest Handler. The …

Jul 4, 2026
CVE-2026-14623
4.3 MEDIUM

A vulnerability was determined in omec-project amf up to 2.1.1. This issue affects the function RRCInactiveTransitionReport of the component NGAP Message Handler. Executing a manipulation …

Jul 4, 2026
CVE-2026-14622
7.3 HIGH

A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. This vulnerability affects unknown code of the file /admin/ajax_files of the component AJAX Endpoint. Performing …

Jul 4, 2026
CVE-2026-14621
3.1 LOW

A vulnerability has been found in FederatedAI FATE up to 2.2.0. This affects the function QueuePushReqStreamObserver.initEggroll of the file java/osx/osx-broker/src/main/java/org/fedai/osx/broker/grpc/QueuePushReqStreamObserver.java of the component OSX Broker. …

Jul 4, 2026
CVE-2026-14619
6.3 MEDIUM

A flaw has been found in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /medicine.php. This manipulation …

Jul 4, 2026
CVE-2026-12194

PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the …

Jul 4, 2026
CVE-2026-14618
4.3 MEDIUM

A vulnerability was detected in Open5GS up to 2.7.7. Affected by this vulnerability is the function amf_nnrf_handle_nf_discover of the file src/amf/nnrf-handler.c of the component AMF. …

Jul 4, 2026
CVE-2026-12252
7.8 HIGH

In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulnerable to untrusted JAR code execution. These classes …

Jul 4, 2026
CVE-2025-71380
8.8 HIGH

The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or …

Jul 4, 2026
CVE-2025-71375
8.1 HIGH

picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can craft malicious pickle payloads using _operator.methodcaller …

Jul 4, 2026
CVE-2025-71373
8.1 HIGH

picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle payloads …

Jul 4, 2026
CVE-2025-71372
8.1 HIGH

Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files that execute …

Jul 4, 2026
CVE-2025-71369
8.1 HIGH

picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basichandlers in reduce methods, allowing attackers to bypass safety checks. Remote attackers can embed …

Jul 4, 2026
CVE-2025-71367
8.1 HIGH

picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in pickle payloads, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle files …

Jul 4, 2026
CVE-2025-71366
8.1 HIGH

picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle files, allowing attackers to bypass safety checks. Remote attackers can embed undetected code …

Jul 4, 2026
CVE-2025-71364
8.1 HIGH

picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle reduce methods, allowing remote code execution. Attackers can craft malicious pickle files embedding this …

Jul 4, 2026
CVE-2025-71362
8.1 HIGH

picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbitrary strings. Attackers can embed malicious code in pickle files that …

Jul 4, 2026
CVE-2025-71360
8.1 HIGH

picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.calltip.get_entity function in reduce methods. Attackers can embed undetected code in pickle files that executes …

Jul 4, 2026
CVE-2025-71359
8.1 HIGH

picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in the reduce method, allowing remote code execution. Attackers can craft pickle files …

Jul 4, 2026
CVE-2025-71356
8.1 HIGH

picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression function calls in pickle files. Attackers can embed undetected code in pickle files that executes remote code …

Jul 4, 2026
CVE-2025-71353
8.1 HIGH

picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get function in reduce methods. Attackers can craft pickle files with embedded code that …

Jul 4, 2026
CVE-2025-71347
8.1 HIGH

picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in reduce methods, allowing attackers to bypass security checks. Remote attackers can embed …

Jul 4, 2026
CVE-2025-71345
8.1 HIGH

picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function. Attackers can embed undetected code in pickle files that executes during deserialization, …

Jul 4, 2026
CVE-2025-71343
8.1 HIGH

picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_label function in the reduce method. Attackers can craft malicious pickle files with embedded …

Jul 4, 2026
CVE-2025-71342
8.1 HIGH

picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. Attackers can embed undetected code in pickle files that executes during …

Jul 4, 2026
CVE-2026-54424
8.4 HIGH

An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through …

Jul 4, 2026
CVE-2026-58523
6.5 MEDIUM

Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.

Jul 3, 2026
CVE-2026-14617
3.1 LOW

A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected is the function GatewayStreamConsumer._filter_and_accumulate of the file gateway/stream_consumer.py of the component Streaming …

Jul 3, 2026
CVE-2026-58597
4.3 MEDIUM

Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Jul 3, 2026
CVE-2026-58524
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Jul 3, 2026
CVE-2026-58522
6.8 MEDIUM

Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

Jul 3, 2026
CVE-2026-58426
9.6 CRITICAL

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

Jul 3, 2026
CVE-2026-58424
8.9 HIGH

Permanent Fork PR Workflow Approval Gate Bypass

Jul 3, 2026
CVE-2026-58423
7.7 HIGH

LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

Jul 3, 2026
CVE-2026-58422
9.8 CRITICAL

Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts

Jul 3, 2026
CVE-2026-58421
7.5 HIGH

Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service

Jul 3, 2026
CVE-2026-58419
7.5 HIGH

Notification API leaks private issue metadata after access revocation

Jul 3, 2026
CVE-2026-58418
6.5 MEDIUM

SSRF via HTTP Redirect in Repository Migration

Jul 3, 2026
CVE-2026-58300
6.2 MEDIUM

Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

Jul 3, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.