CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-101917
5.3 MEDIUM

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT get_signing_key_from_jwt is affected because unknown kid misses force refreshes without a …

Sep 28, 2026
CVE-2026-101146
4.3 MEDIUM

A security flaw has been discovered in Eleveo Quality Management 9.7.0. This issue affects the function UtilsService.createAndSaveAudit of the file /qm/cz.zoom.scorecard.webui.Scorecard/QMUtilsService of the component GWT …

Sep 28, 2026
CVE-2026-101145
4.3 MEDIUM

A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/userAddAction.do of the component User Management. Such …

Sep 28, 2026
CVE-2026-101144
6.3 MEDIUM

A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/searchAction.do of the component Query Builder. This …

Sep 28, 2026
CVE-2026-100370
4.7 MEDIUM

DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.15, the isDangerousUrl() method is responsible for rejecting dangerous URL values in the href …

Sep 28, 2026
CVE-2026-101914
6.5 MEDIUM

@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1.14.1, the exact path (method name) matcher …

Sep 28, 2026
CVE-2026-101143
4.3 MEDIUM

A vulnerability was found in Eleveo Quality Management 9.7.0. Affected by this issue is some unknown functionality of the file /qm/cz.zoom.scorecard.webui.Scorecard/cz.zoom.scorecard.webui.Scorecard/QMBODownload. The manipulation results in …

Sep 28, 2026
CVE-2026-101142
6.3 MEDIUM

A vulnerability has been found in Eleveo Quality Management 9.7.0. Affected by this vulnerability is an unknown functionality of the file Scorecard.jsp of the component …

Sep 28, 2026
CVE-2026-97686
5.5 MEDIUM

Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and …

Sep 28, 2026
CVE-2026-13018
4.3 MEDIUM

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially perform out of bounds memory access …

Sep 28, 2026
CVE-2026-101111
6.1 MEDIUM

Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6 - The public book-detail page template, site/views/view_book/tmpl/default.php, echoes the raw title …

Sep 28, 2026
CVE-2026-101105
6.3 MEDIUM

A vulnerability was determined in code-projects Matrimonial System 1.0. The affected element is the function processprofile_form of the file /create_profile of the component Profile Creation …

Sep 28, 2026
CVE-2026-96740
6.5 MEDIUM

A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api …

Sep 28, 2026
CVE-2026-55156
5.3 MEDIUM

Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to …

Sep 28, 2026
CVE-2026-101102
6.3 MEDIUM

A vulnerability was found in deepseek-ai deepseek-harness up to 0.1.0-rc.7. Impacted is the function run_code of the component Code Mode Sandbox. The manipulation results in …

Sep 28, 2026
CVE-2026-101101
4.3 MEDIUM

A vulnerability has been found in ag-ui-protocol ag-ui up to 2026-09-07. This issue affects the function JSON.parse of the file legacy/convert.ts of the component Middleware. …

Sep 28, 2026
CVE-2026-101100
5.4 MEDIUM

A flaw has been found in ag-ui-protocol ag-ui up to 2026-09-07. This vulnerability affects the function FilterToolCallsMiddleware of the file sdks/typescript/packages/client/src/middleware/filter-tool-calls.ts of the component Middleware. …

Sep 28, 2026
CVE-2026-101099
4.3 MEDIUM

A vulnerability was detected in ag-ui-protocol ag-ui up to 2026-09-23. This affects an unknown part of the file SseParser.kt of the component Kotlin Community SDK. …

Sep 28, 2026
CVE-2026-88815
6.2 MEDIUM

DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv. When casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length …

Sep 28, 2026
CVE-2026-101098
4.3 MEDIUM

A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the function readAllBytes of the file JdkAgentHttpHandler.java of …

Sep 28, 2026
CVE-2026-101083
5.3 MEDIUM

A security vulnerability has been detected in PMWeb v7.x/v8.x/v2025.x. Impacted is an unknown function in the library encryptionhelper.dll. Such manipulation leads to information disclosure. The …

Sep 28, 2026
CVE-2026-101082
5.3 MEDIUM

A weakness has been identified in PMWeb 7.x/8.x/2025.x. This issue affects some unknown processing of the file downloader.aspx. This manipulation of the argument FullFileName/FileName causes …

Sep 28, 2026
CVE-2026-101861
4.1 MEDIUM

Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing …

Sep 28, 2026
CVE-2026-101080
4.8 MEDIUM

A vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.2. This affects the function startsWith of the file skill_scan/tools/dir/dir_actions.py of the component File Access. The …

Sep 28, 2026
CVE-2026-101078
6.3 MEDIUM

A vulnerability has been found in deepseek-ai deepseek-harness up to 0.1.7-rc.2. Affected is an unknown function of the file packages/sandbox/sandbox-local/src/profiles.ts of the component Landlock Backend. …

Sep 28, 2026
CVE-2026-93540
6.5 MEDIUM

A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, the resulting namespace metadata …

Sep 28, 2026
CVE-2026-93539
5.4 MEDIUM

A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted …

Sep 28, 2026
CVE-2026-80359
6.8 MEDIUM

Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU …

Sep 28, 2026
CVE-2026-80358
5.1 MEDIUM

Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU …

Sep 28, 2026
CVE-2026-70413
5.6 MEDIUM

Dell Live Optics Collector, versions prior to 27.2.13.310, contain(s) a Use of Hard-coded Password vulnerability. A low privileged attacker with local access could potentially exploit …

Sep 28, 2026
CVE-2026-93537
6.5 MEDIUM

A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to …

Sep 28, 2026
CVE-2026-87798
5.8 MEDIUM

Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, …

Sep 28, 2026
CVE-2026-86335
6.3 MEDIUM

Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects …

Sep 28, 2026
CVE-2026-86334
4.2 MEDIUM

Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms …

Sep 28, 2026
CVE-2026-15953
5.0 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and …

Sep 28, 2026
CVE-2026-15952
6.4 MEDIUM

Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through …

Sep 28, 2026
CVE-2026-101071
6.3 MEDIUM

A vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects unknown code of the file /exchange/attachment/upload of the component …

Sep 28, 2026
CVE-2026-101070
5.3 MEDIUM

A security vulnerability has been detected in dbgate up to 7.3.1. Affected by this vulnerability is the function files of the file packages/api/src/controllers/runners.js of the …

Sep 28, 2026
CVE-2026-82326
4.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows XSS Targeting HTML Attributes. This issue …

Sep 28, 2026
CVE-2026-59563
4.6 MEDIUM

Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP …

Sep 28, 2026
CVE-2026-101069
6.5 MEDIUM

A weakness has been identified in dbgate up to 7.3.1. Affected is the function exportModelSql of the file packages/api/src/controllers/databaseConnections.js of the component Export Handler. Executing …

Sep 28, 2026
CVE-2026-101068
6.5 MEDIUM

A security flaw has been discovered in dbgate up to 7.3.1. This impacts the function zipJsonLinesData of the file packages/api/src/utility/zipJsonLinesData.js of the component Create Connection …

Sep 28, 2026
CVE-2026-101055
5.3 MEDIUM

A security flaw has been discovered in Thinkware U3000 up to 1.02.04. Affected by this vulnerability is the function GET_STATUS of the component TCP Service. …

Sep 28, 2026
CVE-2026-87752
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Rolantis Information Technologies Tourism Industry and Trade Co. Ltd. Agentis allows XSS Targeting …

Sep 28, 2026
CVE-2026-19444
6.5 MEDIUM

A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When copying files from a container, kubectl runs tar …

Sep 28, 2026
CVE-2026-101054
5.3 MEDIUM

A vulnerability was identified in Thinkware U3000 up to 1.02.04. Affected is the function get_file of the file /tmp/wpa_supplicant.conf of the component TCP Service. The …

Sep 28, 2026
CVE-2026-101040
6.5 MEDIUM

A security flaw has been discovered in Ricoh SP 330DN, SP 221, SP C252SF and Aficio SP 3500SF up to 20260813. This affects an unknown …

Sep 28, 2026
CVE-2026-101036
5.3 MEDIUM

A vulnerability has been found in FLB-Music FLB-Music-Player 1.1.8/1.1.9/1.2.0/1.2.1. This impacts the function path.join of the file /src/main/core/createParsedTrack.ts. The manipulation leads to path traversal. The …

Sep 28, 2026
CVE-2026-101035
5.3 MEDIUM

A flaw has been found in aligungr UERANSIM up to 3.3.0. This affects the function DecodePlainMmMessage in the library src/lib/nas/encode.cpp of the component nr-gnb. Executing …

Sep 28, 2026
CVE-2026-101018
4.7 MEDIUM

A vulnerability was determined in dayrui XunruiCMS up to 4.7.2. This issue affects the function group_all_edit of the file dayrui/App/Member/Controllers/Admin/Home.php of the component Group Editing. …

Sep 28, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.