CVE Database

48111+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-100765
8.8 HIGH

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.

Sep 29, 2026
CVE-2026-100764
8.8 HIGH

Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.

Sep 29, 2026
CVE-2026-100761
8.8 HIGH

Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.

Sep 29, 2026
CVE-2026-100759
8.1 HIGH

Uninitialized memory in the Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox …

Sep 29, 2026
CVE-2026-100757
8.8 HIGH

Use-after-free in the Widget component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and …

Sep 29, 2026
CVE-2026-100756
8.1 HIGH

Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox …

Sep 29, 2026
CVE-2026-95520
7.1 HIGH

A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes …

Sep 29, 2026
CVE-2026-87748
8.8 HIGH

Missing Authorization vulnerability in Interprobe Information Technologies Inc. Qorela DC allows Privilege Abuse. This issue affects Qorela DC: from 1.6.1-RC29 before v1.6.2.

Sep 29, 2026
CVE-2026-102497
7.5 HIGH

The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model groups or attribute groups. A malicious schema with such a cycle …

Sep 29, 2026
CVE-2026-102496
7.5 HIGH

Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make parsing recurse …

Sep 29, 2026
CVE-2026-102495
7.5 HIGH

Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows. …

Sep 29, 2026
CVE-2026-95389
8.1 HIGH

SCTP protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Sep 29, 2026
CVE-2026-95387
8.1 HIGH

SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Sep 29, 2026
CVE-2026-84739
8.7 HIGH

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain …

Sep 29, 2026
CVE-2026-76719
8.2 HIGH

A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unauthorized actions.

Sep 29, 2026
CVE-2026-76718
8.2 HIGH

A potential security vulnerability in HPE OneView can be exploited to allow remote session hijacking or other unauthorized actions.

Sep 29, 2026
CVE-2026-92142
8.8 HIGH

Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role-based access control (RBAC) on MBean operations invoked over the remote JMX connector (RMI …

Sep 29, 2026
CVE-2026-86158
7.7 HIGH

Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a local unauthenticated attacker to mint OAuth tokens and read …

Sep 29, 2026
CVE-2026-102293
7.3 HIGH

A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the function OrgStaffServiceImpl.add of the file ApiMaApplication.java of the component api-admin Backend. The manipulation of …

Sep 29, 2026
CVE-2026-97024
7.1 HIGH

A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files …

Sep 29, 2026
CVE-2026-102422
8.1 HIGH

shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including …

Sep 29, 2026
CVE-2026-102249
7.3 HIGH

A security flaw has been discovered in REBUILD up to 4.4.11. This vulnerability affects unknown code of the file /commons/file-editor-save. The manipulation of the argument …

Sep 29, 2026
CVE-2026-102248
7.3 HIGH

A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of the file /user/login of the component Login Endpoint. The manipulation …

Sep 29, 2026
CVE-2026-102245
7.3 HIGH

A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component …

Sep 29, 2026
CVE-2026-102243
7.4 HIGH

A vulnerability was identified in MODSetter SurfSense up to 2.0.3. This issue affects some unknown processing of the file /api/search-source/connectors/mcp/test of the component MCP Connector …

Sep 29, 2026
CVE-2026-96326
7.2 HIGH

The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text …

Sep 29, 2026
CVE-2026-101878
7.5 HIGH

Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently truncating …

Sep 29, 2026
CVE-2026-101860
8.8 HIGH

A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component …

Sep 29, 2026
CVE-2026-101281
7.3 HIGH

A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c …

Sep 29, 2026
CVE-2026-101280
7.3 HIGH

A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation …

Sep 29, 2026
CVE-2026-102335
7.1 HIGH

Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers …

Sep 28, 2026
CVE-2026-102334
7.4 HIGH

Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login …

Sep 28, 2026
CVE-2026-102281
7.5 HIGH

Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a single message with a deeply nested object in its …

Sep 28, 2026
CVE-2026-101188
8.3 HIGH

A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638. This issue affects the function routerd.passwd_set of the file /ubus. Such manipulation leads to weak …

Sep 28, 2026
CVE-2026-101091
7.1 HIGH

SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers can craft malicious .sy documents with …

Sep 28, 2026
CVE-2024-42002
8.4 HIGH

A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal …

Sep 28, 2026
CVE-2026-91096
7.5 HIGH

In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destroy in releases before v2025.08.18.00) failed to unregister read callbacks for streams that were no longer open before …

Sep 28, 2026
CVE-2026-84895
7.3 HIGH

In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies the session handler, which …

Sep 28, 2026
CVE-2026-18414
7.8 HIGH

The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h …

Sep 28, 2026
CVE-2026-18413
7.8 HIGH

The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h …

Sep 28, 2026
CVE-2026-16513
7.8 HIGH

The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/rtio/rtio_handlers.c before v4.3.0) validated the RTIO object handle and the sqes input array, but not the handle out-parameter. On …

Sep 28, 2026
CVE-2026-102278
7.5 HIGH

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() …

Sep 28, 2026
CVE-2026-102276
7.5 HIGH

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the …

Sep 28, 2026
CVE-2026-102273
7.4 HIGH

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because HMAC key guard only recognizes top-level …

Sep 28, 2026
CVE-2026-102272
7.4 HIGH

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_key in jwt/algorithms.py is affected because raw-JWK detector does not normalize …

Sep 28, 2026
CVE-2026-102271
7.4 HIGH

PyJWT is a Python implementation of JSON Web Token standards. From 2.4.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because asymmetric-key guard relies on textual markers …

Sep 28, 2026
CVE-2026-102267
7.4 HIGH

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is affected because redirect destinations are not revalidated against the …

Sep 28, 2026
CVE-2026-102266
7.4 HIGH

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.from_jwk is affected because PyJWK verification path used the decoded key …

Sep 28, 2026
CVE-2026-101916
7.4 HIGH

@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, getAuthContext does not distinguish authorized from …

Sep 28, 2026
CVE-2026-93355
8.1 HIGH

LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user …

Sep 28, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.