CVE Database

47974+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-106503
8.1 HIGH

Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by scaffolder action input …

Oct 6, 2026
CVE-2026-106500
8.5 HIGH

Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper task state …

Oct 6, 2026
CVE-2026-106498
7.7 HIGH

Backstage is an open framework for building developer portals. Prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1, the @backstage/plugin-catalog-backend package is affected by improper url …

Oct 6, 2026
CVE-2026-105267
8.1 HIGH

The Gitea web route for deleting tags (`POST /{owner}/{repo}/tags/delete`) requires only write access to the Code unit, but shares its handler with release deletion and …

Oct 6, 2026
CVE-2026-106550
7.5 HIGH

Mozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of Service vulnerability caused by incomplete prototype‑pollution protections in config.set(). An attacker controlling the …

Oct 6, 2026
CVE-2026-106492
7.6 HIGH

Backstage is an open framework for building developer portals. Prior to 0.16.1 and 0.17.8, the @backstage/backend-defaults package is affected by improper preservation of access restrictions …

Oct 6, 2026
CVE-2026-106488
8.1 HIGH

Backstage is an open framework for building developer portals. Prior to 0.4.20, the @backstage/plugin-auth-backend-module-oidc-provider package is affected by improper authentication in the oidc provider. Deployments …

Oct 6, 2026
CVE-2026-106486
8.5 HIGH

Backstage is an open framework for building developer portals. Prior to 0.3.10 in @backstage/plugin-scaffolder-backend-module-bitbucket-cloud and 0.2.25 in @backstage/plugin-scaffolder-backend-module-bitbucket-server, the Bitbucket pull-request Scaffolder actions did not …

Oct 6, 2026
CVE-2026-106459
8.5 HIGH

Backstage is an open framework for building developer portals. From 0.3.0 until 0.3.8, the @backstage/plugin-scaffolder-backend-module-sentry package is affected by improper input validation in sentry scaffolder …

Oct 6, 2026
CVE-2026-106455
7.7 HIGH

Backstage is an open framework for building developer portals. From 0.11.12 until 1.14.7 and 1.15.5, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs …

Oct 6, 2026
CVE-2026-106062
7.8 HIGH

A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a crafted DDS image, buffer sizes derived from width, height, and …

Oct 6, 2026
CVE-2026-101258
7.8 HIGH

A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell …

Oct 6, 2026
CVE-2026-96580
7.5 HIGH

Gitea expanded a workflow's static `strategy.matrix` into its full Cartesian product without a size limit when creating a run, before the fork pull request approval …

Oct 6, 2026
CVE-2026-96404
8.1 HIGH

When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been reset to `false`, submitting the install …

Oct 6, 2026
CVE-2026-96399
7.5 HIGH

A repository's external issue tracker regular expression containing alternating capture groups could produce invalid slice indexes when Gitea rendered issue references, causing a runtime panic …

Oct 6, 2026
CVE-2026-89430
8.1 HIGH

Gitea validated a push mirror's remote address against the `[migrations]` allow and block lists only when the mirror was created. Each synchronization passed the stored …

Oct 6, 2026
CVE-2026-79960
7.1 HIGH

When a push was authenticated with a deploy key, Gitea recorded the repository owner as the pusher, so permission checks in the push hook pipeline …

Oct 6, 2026
CVE-2026-79811
7.2 HIGH

A SQL injection vulnerability in the API of ClearPass Policy Manager could allow a remote authenticated attacker with administrative privileges to conduct SQL injection attacks …

Oct 6, 2026
CVE-2026-79810
7.2 HIGH

Remote code execution vulnerabilities exist in the affected interface of HPE Networking ClearPass Policy Manager that could allow an authenticated remote attacker with high privileges …

Oct 6, 2026
CVE-2026-79809
7.3 HIGH

An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manager. Successful exploitation of this vulnerability allows an unauthenticated remote attacker to …

Oct 6, 2026
CVE-2026-79808
7.8 HIGH

A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an authenticated local user to execute arbitrary code …

Oct 6, 2026
CVE-2026-79807
7.8 HIGH

A missing integrity verification vulnerability in the Windows client software for ClearPass Policy Manager could allow malicious users on a local instance to elevate their …

Oct 6, 2026
CVE-2026-79806
7.8 HIGH

A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. …

Oct 6, 2026
CVE-2026-79803
8.8 HIGH

A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful exploitation could allow an authenticated remote attacker to escalate privileges and gain …

Oct 6, 2026
CVE-2026-79802
8.8 HIGH

A command injection vulnerability exists in the client software of ClearPass Policy Manager. Successful exploitation could allow an attacker who is able to supply crafted …

Oct 6, 2026
CVE-2026-79800
8.8 HIGH

An authenticated path traversal vulnerability exists in the command line interface of ClearPass Policy Manager. Successful exploitation could allow a low-privileged authenticated remote attacker to …

Oct 6, 2026
CVE-2026-79799
8.8 HIGH

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack …

Oct 6, 2026
CVE-2026-79797
8.8 HIGH

An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted …

Oct 6, 2026
CVE-2026-76748
8.8 HIGH

A privilege escalation vulnerability exists in the API of AOS-S. Successful exploitation could allow an authenticated read-only user to escalate their privileges and gain administrative …

Oct 6, 2026
CVE-2026-70357
7.5 HIGH

Gitea validates a repository migration hostname against its network allow and block lists before invoking Git, but the Git subprocess independently resolves the hostname when …

Oct 6, 2026
CVE-2026-104636
7.5 HIGH

Gitea validated the initial remote URL for push mirrors, wiki remote checks, and fetches of migrated pull request heads, but the subsequent raw Git operations …

Oct 6, 2026
CVE-2026-104632
8.8 HIGH

Gitea Actions blocks the jobs of workflow runs from first-time fork pull request contributors until a maintainer approves the run. The rerun path only required …

Oct 6, 2026
CVE-2026-104626
8.8 HIGH

A user who can open a fork pull request can place workflow content with a shared run-level concurrency group into a Gitea Actions run that …

Oct 6, 2026
CVE-2026-103670
7.5 HIGH

When a Gitea Actions run was inserted, older runs in the same workflow-level concurrency group were cancelled without checking whether the new run still needed …

Oct 6, 2026
CVE-2026-103504
8.1 HIGH

Changing an organization team's permission through the API with only the `permission` field did not rebuild the team's per-unit access, and the requested level was …

Oct 6, 2026
CVE-2026-103009
7.1 HIGH

Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information Disclosure via a specially crafted cross-cluster search request that references an unauthorized shard …

Oct 6, 2026
CVE-2026-103007
7.2 HIGH

Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege whose scope is not fully enforced during authorization checks. Elasticsearch …

Oct 6, 2026
CVE-2026-102406
8.8 HIGH

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data interception. In this context, "tenant" refers to a user or team sharing …

Oct 6, 2026
CVE-2026-102167
7.5 HIGH

On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor …

Oct 6, 2026
CVE-2026-102165
7.5 HIGH

On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the capture service can send a crafted packet to cause the service …

Oct 6, 2026
CVE-2026-102163
8.8 HIGH

On affected Arista access points with Wireless Intrusion Prevention System (WIPS) active, an unauthenticated attacker within radio frequency (RF) proximity can send a crafted frame …

Oct 6, 2026
CVE-2026-102162
8.8 HIGH

On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service …

Oct 6, 2026
CVE-2026-102161
8.8 HIGH

An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their …

Oct 6, 2026
CVE-2026-102160
7.2 HIGH

An operating system (OS) command injection vulnerability in CloudVision CUE backup management may allow an authenticated Super User to submit a crafted backup request and …

Oct 6, 2026
CVE-2026-102155
8.5 HIGH

An XML External Entity (XXE) injection vulnerability in the WiFi-server Spectralight application allows any authenticated user to send malicious requests, leading to arbitrary local file …

Oct 6, 2026
CVE-2026-101158
8.4 HIGH

A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful …

Oct 6, 2026
CVE-2026-101157
8.7 HIGH

A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacent-network access to inject malicious content that executes when an authenticated user views …

Oct 6, 2026
CVE-2026-101156
8.4 HIGH

A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege administrator to store malicious content in a configuration. The content may execute in another …

Oct 6, 2026
CVE-2026-101154
7.2 HIGH

An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or …

Oct 6, 2026
CVE-2026-101153
8.0 HIGH

On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this …

Oct 6, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.