CVE Database

10684+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-71327
9.1 CRITICAL

Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. Remote attackers can exploit this endpoint …

Jun 25, 2026
CVE-2026-56445
9.1 CRITICAL

The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths.

Jun 25, 2026
CVE-2026-7531
9.8 CRITICAL

Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 server sending a truncated PQC …

Jun 25, 2026
CVE-2026-57700
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6.

Jun 25, 2026
CVE-2026-56786
9.8 CRITICAL

RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp length counters to destination buffer size, allowing up to 191-byte …

Jun 25, 2026
CVE-2026-54917
10.0 CRITICAL

SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the S3 API gateway and the Iceberg …

Jun 25, 2026
CVE-2026-54089
9.1 CRITICAL

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Starting with 2.0.0-rc.1, when FileBrowser is …

Jun 25, 2026
CVE-2026-50549
9.8 CRITICAL

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a …

Jun 25, 2026
CVE-2026-50548
9.8 CRITICAL

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the …

Jun 25, 2026
CVE-2026-6094
9.1 CRITICAL

Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered via S/MIME or CMS.

Jun 25, 2026
CVE-2026-54849
9.3 CRITICAL

Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.

Jun 25, 2026
CVE-2026-54843
9.3 CRITICAL

Unauthenticated SQL Injection in MDTF <= 1.3.7 versions.

Jun 25, 2026
CVE-2026-54836
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection. This issue affects YMC Filter: from …

Jun 25, 2026
CVE-2026-54823
9.9 CRITICAL

Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.

Jun 25, 2026
CVE-2026-41120
9.8 CRITICAL

Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability. A low privileged attacker …

Jun 25, 2026
CVE-2026-53260
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). syzbot reported a weird reqsk->rsk_refcnt underflow in __inet_csk_reqsk_queue_drop(). The captured …

Jun 25, 2026
CVE-2026-53247
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown mtk_free_dev() calls metadata_dst_free() which frees the …

Jun 25, 2026
CVE-2026-53246
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing When a listening SCTP server …

Jun 25, 2026
CVE-2026-53228
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner IPv6 header after GSO offloads ipip6_tunnel_xmit() caches the inner IPv6 header …

Jun 25, 2026
CVE-2026-53225
9.1 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can …

Jun 25, 2026
CVE-2026-53224
9.1 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address list lengths in cookie sctp_unpack_cookie() only checked that …

Jun 25, 2026
CVE-2026-53221
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() In vti6_tnl_lookup(), when an exact match for a …

Jun 25, 2026
CVE-2026-53216
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer mvpp2 has short and long …

Jun 25, 2026
CVE-2026-53215
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or skb use The RX error path returns …

Jun 25, 2026
CVE-2026-53186
9.1 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: bound SRP_RSP sense copy by the received length srp_process_rsp() copies sense data from rsp->data …

Jun 25, 2026
CVE-2026-53176
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN In drivers/infiniband/ulp/isert/ib_isert.c, isert_login_recv_done() computes the login request payload …

Jun 25, 2026
CVE-2026-53175
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush On netns teardown, fqdir_pre_exit() walks the …

Jun 25, 2026
CVE-2026-53151
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the ACK parser to extract the SACK table for parsing Fix modification of …

Jun 25, 2026
CVE-2026-53131
9.4 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using eth_hdr() `ip6t_eui64`, `xt_mac`, the `bitmap:ip,mac`, `hash:ip,mac`, and `hash:mac` …

Jun 25, 2026
CVE-2026-40079
9.8 CRITICAL

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization in …

Jun 25, 2026
CVE-2026-39955
9.8 CRITICAL

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php. This issue …

Jun 24, 2026
CVE-2026-39948
9.8 CRITICAL

Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request parameter is retrieved via the raw accessor …

Jun 24, 2026
CVE-2026-39938
9.8 CRITICAL

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtool IPC serialization hardening. This …

Jun 24, 2026
CVE-2026-55570
9.0 CRITICAL

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, description) when they are …

Jun 24, 2026
CVE-2026-55455
9.1 CRITICAL

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filter applied by WebClientUtils (used by …

Jun 24, 2026
CVE-2026-55454
9.9 CRITICAL

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-proxy's admin API — which has no …

Jun 24, 2026
CVE-2026-54158
9.9 CRITICAL

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolates cell content raw in four of its …

Jun 24, 2026
CVE-2026-54067
9.9 CRITICAL

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> breaks out of its surrounding <style> tag when renderSnippet() …

Jun 24, 2026
CVE-2026-50551
9.9 CRITICAL

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in the Attribute View (database) asset …

Jun 24, 2026
CVE-2026-39893
9.8 CRITICAL

Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request variable was concatenated into a RLIKE SQL …

Jun 24, 2026
CVE-2026-52813
10.0 CRITICAL

Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under …

Jun 24, 2026
CVE-2026-52806
9.9 CRITICAL

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by …

Jun 24, 2026
CVE-2026-45689
9.1 CRITICAL

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, an unauthenticated network attacker obtains …

Jun 24, 2026
CVE-2026-45688
9.1 CRITICAL

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's CAS login handler forwards …

Jun 24, 2026
CVE-2026-53943
9.6 CRITICAL

Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that results in cached content being shared …

Jun 24, 2026
CVE-2026-49980
9.8 CRITICAL

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts …

Jun 24, 2026
CVE-2026-13032
9.6 CRITICAL

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a …

Jun 24, 2026
CVE-2026-13028
9.6 CRITICAL

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a …

Jun 24, 2026
CVE-2026-54906
9.8 CRITICAL

concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock does not verify that the calling thread acquired the write lock. Any thread …

Jun 24, 2026
CVE-2026-53088
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb The write_ptr points to the next open tx_cb. We …

Jun 24, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.