CVE Database

48111+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-87741
8.8 HIGH

The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of …

Sep 28, 2026
CVE-2026-86950
8.8 HIGH KEV

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe …

Sep 28, 2026
CVE-2026-102004
7.8 HIGH

Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in memory corruption within the memory management subsystem. Fixed in Version 26.09

Sep 28, 2026
CVE-2026-97023
7.1 HIGH

A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files …

Sep 28, 2026
CVE-2026-84894
7.5 HIGH

In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a FIN, which invalidates the handle under proxygen's WebTransport API. A …

Sep 28, 2026
CVE-2026-102010
7.0 HIGH

A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage …

Sep 28, 2026
CVE-2026-55160
7.6 HIGH

Stringer is a self-hosted, anti-social RSS reader. Prior to commit 75cb095, an unrestricted Server-Side Request Forgery (SSRF) vulnerability allows any authenticated user to force the …

Sep 28, 2026
CVE-2026-55157
8.4 HIGH

Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to …

Sep 28, 2026
CVE-2026-88816
7.5 HIGH

DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName. fetchrow_hashref uses the string pointer of the FetchHashKeyName attribute as the …

Sep 28, 2026
CVE-2026-87114
7.1 HIGH

A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting …

Sep 28, 2026
CVE-2026-85644
7.5 HIGH

XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference. The wrapper function XS::Parse::Infix generates for a list-associative infix operator …

Sep 28, 2026
CVE-2026-55096
7.1 HIGH

fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_phone MCP tools accept files as a list of http(s) URLs, which the server …

Sep 28, 2026
CVE-2026-54160
8.2 HIGH

Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware. Prior to commits …

Sep 28, 2026
CVE-2026-93348
8.1 HIGH

Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19, contains a code injection vulnerability in the model-loading compile path where the …

Sep 28, 2026
CVE-2026-88808
8.8 HIGH

A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the …

Sep 28, 2026
CVE-2026-88805
8.1 HIGH

Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE …

Sep 28, 2026
CVE-2026-93538
7.1 HIGH

A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the …

Sep 28, 2026
CVE-2026-80357
7.0 HIGH

Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU …

Sep 28, 2026
CVE-2026-4556
7.8 HIGH

Exam4 is affected by a local privilege escalation vulnerability in the com.extegrity.LogTool privileged helper, which communicates with the application via XPC. The [ConsoleLogHelper copyConsoleIntoFileFromStartDate:] method …

Sep 28, 2026
CVE-2026-101073
8.3 HIGH

A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa of the component CGI Dispatcher. Performing …

Sep 28, 2026
CVE-2026-97335
7.7 HIGH

Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows …

Sep 28, 2026
CVE-2026-90926
8.8 HIGH

Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue …

Sep 28, 2026
CVE-2026-90925
7.1 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Path …

Sep 28, 2026
CVE-2026-86595
8.8 HIGH

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows SQL Injection. This issue …

Sep 28, 2026
CVE-2026-86330
7.2 HIGH

An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in …

Sep 28, 2026
CVE-2026-82323
8.1 HIGH

Authorization bypass through User-Controlled key vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows Exploitation of Trusted Identifiers. This issue affects Enocta Platform: through 2026-09-28.

Sep 28, 2026
CVE-2026-12265
8.8 HIGH

Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations.

Sep 28, 2026
CVE-2026-101292
8.2 HIGH

Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol …

Sep 28, 2026
CVE-2026-101067
7.3 HIGH

A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile of the file files.js of the component save-uploaded-file Endpoint. Such manipulation …

Sep 28, 2026
CVE-2026-101066
7.3 HIGH

A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link …

Sep 28, 2026
CVE-2026-78424
8.8 HIGH

Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector’s internal gRPC …

Sep 28, 2026
CVE-2026-12264
8.8 HIGH

Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config sync upload leading to remote code execution.

Sep 28, 2026
CVE-2026-101053
7.3 HIGH

A vulnerability was determined in Thinkware U3000 up to 1.02.04. This impacts the function PUT_FILE of the file /tmp/wpa_supplicant.conf of the component TCP Service. Executing …

Sep 28, 2026
CVE-2026-101052
7.3 HIGH

A security vulnerability has been detected in refly-ai refly up to 1.1.0. This issue affects some unknown processing of the file apps/api/src/modules/config/app.config.ts of the component …

Sep 28, 2026
CVE-2026-91006
8.8 HIGH

Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) …

Sep 28, 2026
CVE-2026-12269
8.8 HIGH

Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated …

Sep 28, 2026
CVE-2026-12268
8.8 HIGH

ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution.

Sep 28, 2026
CVE-2026-12267
7.2 HIGH

ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution.

Sep 28, 2026
CVE-2026-90979
7.3 HIGH

LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and role lookup by textually substituting the placeholders %u, %dn, and %fqdn (drawn from the …

Sep 28, 2026
CVE-2026-95104
7.5 HIGH

Stack-based buffer overflow vulnerability exists in BUFFALO Wi-Fi products. A non-authenticated crafted HTTP request may cause a denial-of-service (DoS) condition.

Sep 28, 2026
CVE-2026-94286
7.1 HIGH

An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients.

Sep 28, 2026
CVE-2026-86530
7.2 HIGH

BUFFALO Wi-Fi products handle some web form input improperly to assemble command line strings internally. An administrative user may send a crafted HTTP request and …

Sep 28, 2026
CVE-2026-85134
8.8 HIGH

Unrestricted upload of file with dangerous type vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Upload a Web …

Sep 28, 2026
CVE-2026-101015
7.3 HIGH

A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is some unknown functionality of the file policy.c …

Sep 28, 2026
CVE-2026-101014
7.3 HIGH

A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of …

Sep 28, 2026
CVE-2026-82386
7.7 HIGH

Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files readable by the Roller process and reach …

Sep 28, 2026
CVE-2026-82383
8.2 HIGH

Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote attacker to persistently change a site-global configuration value (the frontpage weblog selection) …

Sep 28, 2026
CVE-2026-82380
8.1 HIGH

Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a logged-in user to perform state-changing actions under the victim's authority, …

Sep 28, 2026
CVE-2026-82379
7.7 HIGH

Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authentication header to replay it and gain the …

Sep 28, 2026
CVE-2026-82376
7.7 HIGH

Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entry-editing rights on a weblog to cause the server to …

Sep 28, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.