CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-78214
5.3 MEDIUM

An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication is required by matching the incoming request path against …

Sep 29, 2026
CVE-2026-71899
6.5 MEDIUM

A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to …

Sep 29, 2026
CVE-2026-71898
4.3 MEDIUM

An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that …

Sep 29, 2026
CVE-2026-71897
4.3 MEDIUM

An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for …

Sep 29, 2026
CVE-2026-98164
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address spaces kvm_gfn_is_write_tracked() checks only the supplied memslot, …

Sep 29, 2026
CVE-2026-96869
4.3 MEDIUM

Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR …

Sep 29, 2026
CVE-2026-76875
5.3 MEDIUM

PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module's ExternalEntityParserCreate function that allows attackers to corrupt memory by supplying a …

Sep 29, 2026
CVE-2026-76114
5.9 MEDIUM

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access …

Sep 29, 2026
CVE-2026-73599
5.4 MEDIUM

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with …

Sep 29, 2026
CVE-2026-100826
6.5 MEDIUM

Denial-of-service in the Storage: StorageManager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.

Sep 29, 2026
CVE-2026-100823
5.4 MEDIUM

Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157.

Sep 29, 2026
CVE-2026-100822
5.4 MEDIUM

Spoofing issue in the Networking: HTTP component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.

Sep 29, 2026
CVE-2026-100821
4.7 MEDIUM

Site isolation issue in the Panning and Zooming component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, …

Sep 29, 2026
CVE-2026-100817
5.4 MEDIUM

Other issue in the JavaScript: WebAssembly component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.

Sep 29, 2026
CVE-2026-100812
6.5 MEDIUM

Denial-of-service in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.

Sep 29, 2026
CVE-2026-100806
4.3 MEDIUM

Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.

Sep 29, 2026
CVE-2026-100802
4.3 MEDIUM

Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.

Sep 29, 2026
CVE-2026-100799
4.3 MEDIUM

Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.

Sep 29, 2026
CVE-2026-100795
6.5 MEDIUM

Denial-of-service in the Networking component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.

Sep 29, 2026
CVE-2026-100793
6.5 MEDIUM

JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.

Sep 29, 2026
CVE-2026-100783
4.3 MEDIUM

Uninitialized memory in the Audio/Video component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, …

Sep 29, 2026
CVE-2026-100766
4.3 MEDIUM

Information disclosure in the Networking: JAR component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR …

Sep 29, 2026
CVE-2026-73597
6.5 MEDIUM

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could …

Sep 29, 2026
CVE-2026-73595
4.7 MEDIUM

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Download of Code Without Integrity Check vulnerability. An …

Sep 29, 2026
CVE-2026-73594
6.4 MEDIUM

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with …

Sep 29, 2026
CVE-2026-66083
6.5 MEDIUM

The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are …

Sep 29, 2026
CVE-2026-102507
5.7 MEDIUM

Sliver C2 framework version 1.7.7 and earlier contains an unhandled panic vulnerability in the operator gRPC handler that allows an attacker controlling a compromised implant …

Sep 29, 2026
CVE-2026-96423
5.5 MEDIUM

X11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Sep 29, 2026
CVE-2026-96422
5.5 MEDIUM

Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Sep 29, 2026
CVE-2026-96421
5.5 MEDIUM

USB HID protocol dissector infinite loop and memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Sep 29, 2026
CVE-2026-96420
4.7 MEDIUM

Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Sep 29, 2026
CVE-2026-96419
5.5 MEDIUM

Profile import crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service and possible code execution

Sep 29, 2026
CVE-2026-96418
5.5 MEDIUM

TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Sep 29, 2026
CVE-2026-96417
5.5 MEDIUM

RF4CE protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Sep 29, 2026
CVE-2026-96416
5.5 MEDIUM

IEEE 802.11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Sep 29, 2026
CVE-2026-96415
5.5 MEDIUM

Catapult DCT2000 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Sep 29, 2026
CVE-2026-95395
5.5 MEDIUM

IEEE C37.118 Synchrophasor protocol dissector memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Sep 29, 2026
CVE-2026-95394
4.7 MEDIUM

Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Sep 29, 2026
CVE-2026-95393
4.7 MEDIUM

CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Sep 29, 2026
CVE-2026-95392
5.5 MEDIUM

MBIM protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Sep 29, 2026
CVE-2026-95391
5.5 MEDIUM

ZigBee ZCL protocol dissector crash in 4.6.0 to 4.6.8 allows denial of service

Sep 29, 2026
CVE-2026-95390
5.5 MEDIUM

PEAK CAN TRC file parser crash in 4.6.0 to 4.6.8 allows denial of service

Sep 29, 2026
CVE-2026-95388
5.5 MEDIUM

Sharkd utility crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Sep 29, 2026
CVE-2026-95386
5.5 MEDIUM

TTL file parser infinite loop in 4.6.0 to 4.6.8 allows denial of service

Sep 29, 2026
CVE-2026-8937
4.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain …

Sep 29, 2026
CVE-2026-8067
6.5 MEDIUM

An improper authorization vulnerability in the end-of-life versions of RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset …

Sep 29, 2026
CVE-2026-86843
6.3 MEDIUM

The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the …

Sep 29, 2026
CVE-2026-81930
6.3 MEDIUM

Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built …

Sep 29, 2026
CVE-2026-81914
4.3 MEDIUM

Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into single-quoted string literals, without escaping the quote character …

Sep 29, 2026
CVE-2026-81862
6.5 MEDIUM

Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTeradataOperator` and `AzureBlobStorageToTeradataOperator` interpolate the source bucket's credentials as plain string literals into …

Sep 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.