CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-16318
5.3 MEDIUM

The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store the peer's transport parameters. When a TLS 1.3 connection …

Jul 21, 2026
CVE-2026-16317
6.5 MEDIUM

Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently discard individual application data records …

Jul 21, 2026
CVE-2026-12139
4.4 MEDIUM

Tanium addressed an information disclosure vulnerability in Connect.

Jul 21, 2026
CVE-2026-65069
4.0 MEDIUM

Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in dsu.h …

Jul 21, 2026
CVE-2026-65065
5.5 MEDIUM

Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in roaring.h …

Jul 21, 2026
CVE-2026-64613
6.2 MEDIUM

Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOLLOW. The segment is created in buf_generic.h with open(path, …

Jul 21, 2026
CVE-2026-59143
6.3 MEDIUM

Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offset and cardinality in rb_contains_locked. The attach-time validator rb_validate_header checks the …

Jul 21, 2026
CVE-2026-56146
5.4 MEDIUM

Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with …

Jul 21, 2026
CVE-2026-56145
6.5 MEDIUM

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL …

Jul 21, 2026
CVE-2026-56144
5.3 MEDIUM

Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By …

Jul 21, 2026
CVE-2026-49092
4.3 MEDIUM

Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under …

Jul 21, 2026
CVE-2026-47671
5.4 MEDIUM

Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost configserver` used by `nhost dev` …

Jul 21, 2026
CVE-2026-46403
6.3 MEDIUM

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithTypedArguments` as a read-only execution mechanism. The hook saves the …

Jul 21, 2026
CVE-2026-42397
6.5 MEDIUM

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can …

Jul 21, 2026
CVE-2026-12548
4.2 MEDIUM

A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause …

Jul 21, 2026
CVE-2026-47411
6.5 MEDIUM

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling workspace metadata + settings …

Jul 21, 2026
CVE-2026-47408
6.5 MEDIUM

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The `GET /workspaces/{workspace_id}/issues/{issue_id}/activity` …

Jul 21, 2026
CVE-2026-24232
4.3 MEDIUM

NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code …

Jul 21, 2026
CVE-2026-16454
4.3 MEDIUM

In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identified in the Direct Device Integration (DDI) Controller. This …

Jul 21, 2026
CVE-2026-16451
6.3 MEDIUM

A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the file /api/system/file/upload of the component com.zs.file.controller.SysFileController. …

Jul 21, 2026
CVE-2026-15342
6.5 MEDIUM

Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to …

Jul 21, 2026
CVE-2025-68640
5.3 MEDIUM

The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove …

Jul 21, 2026
CVE-2026-64823
4.7 MEDIUM

Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_media_image() method that allows attackers controlling a Shelly device's thumb field …

Jul 21, 2026
CVE-2026-47395
5.5 MEDIUM

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, PraisonAI's direct-prompt CLI automatically expands `@url:` mentions …

Jul 21, 2026
CVE-2026-47390
5.5 MEDIUM

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `spider_tools` URL validation can be bypassed using …

Jul 21, 2026
CVE-2026-28315
6.2 MEDIUM

SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator …

Jul 21, 2026
CVE-2026-16450
4.3 MEDIUM

A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the function getTenantId of the file /api/system/sys/dept/page of the component MyBatis-Plus Tenant Plugin. …

Jul 21, 2026
CVE-2026-16449
6.3 MEDIUM

A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The impacted element is the function OrderItem.asc/OrderItem.desc of the file /api/system/sys/dept/page of the component com.zs.sys.dept.controller.SysDeptController. …

Jul 21, 2026
CVE-2026-65051
6.5 MEDIUM

Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging …

Jul 21, 2026
CVE-2026-65050
6.5 MEDIUM

Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated …

Jul 21, 2026
CVE-2026-59850
4.3 MEDIUM

A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated …

Jul 21, 2026
CVE-2026-47122
4.2 MEDIUM

Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `shouldAcceptNewConnection:` only enforces `SUCodeSigningVerifier validateConnection:` before stage 1 completes. …

Jul 21, 2026
CVE-2026-16448
6.3 MEDIUM

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 …

Jul 21, 2026
CVE-2026-11876
5.0 MEDIUM

In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/stack` endpoint (`get_deployed_stack`) lacks proper RBAC authorization checks, allowing any authenticated user to enumerate all deployed stacks across all …

Jul 21, 2026
CVE-2024-5300
5.6 MEDIUM

An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd …

Jul 21, 2026
CVE-2026-59848
5.3 MEDIUM

A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded …

Jul 21, 2026
CVE-2026-59847
5.9 MEDIUM

A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker …

Jul 21, 2026
CVE-2026-47121
6.1 MEDIUM

Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `relativePath.pathComponents containsObject:@".."` and rejects writes whose immediate parent directory IS itself …

Jul 21, 2026
CVE-2026-8285
4.3 MEDIUM

Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. FlexCity allows Excessive Allocation. This issue affects FlexCity: from 5.536.0 through 11052026.

Jul 21, 2026
CVE-2026-8284
6.1 MEDIUM

URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data Manipulation. This issue affects FlexCity: from 5.536.0 through 11052026.

Jul 21, 2026
CVE-2026-6792
6.5 MEDIUM

Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCity: from 5.536.0 through 11052026.

Jul 21, 2026
CVE-2026-16403
6.5 MEDIUM

Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16397
6.5 MEDIUM

Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-65009
4.3 MEDIUM

OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint that fails to filter operational logs by realm. Attackers with the …

Jul 21, 2026
CVE-2026-64628
5.4 MEDIUM

Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS detection scan only matches payloads containing literal angle brackets, allowing shortcode …

Jul 21, 2026
CVE-2026-59845
5.3 MEDIUM

A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may …

Jul 21, 2026
CVE-2026-59844
6.5 MEDIUM

A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to …

Jul 21, 2026
CVE-2026-59843
6.5 MEDIUM

A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop …

Jul 21, 2026
CVE-2026-16461
6.5 MEDIUM

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), version numbers from a remote RPCBPROC_DUMP reply …

Jul 21, 2026
CVE-2026-1372
4.3 MEDIUM

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to …

Jul 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.