CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-70480
4.1 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open WebUI renders vega and vega-lite fenced code blocks in …

Aug 4, 2026
CVE-2026-48154
5.9 MEDIUM

GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA contains a …

Aug 4, 2026
CVE-2026-16792
6.1 MEDIUM

An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive …

Aug 4, 2026
CVE-2026-69704
6.5 MEDIUM

Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsanitized input through a GET parameter to the supp() deletion …

Aug 4, 2026
CVE-2026-69702
6.5 MEDIUM

SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated attackers to crash the server by supplying a crafted Zstandard-compressed …

Aug 4, 2026
CVE-2026-68743
5.5 MEDIUM

A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before …

Aug 4, 2026
CVE-2026-66300
5.0 MEDIUM

SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. An attacker can inject arbitrary JavaScript which will execute upon a …

Aug 4, 2026
CVE-2026-47622
5.3 MEDIUM

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive information. A successful exploit of …

Aug 4, 2026
CVE-2026-47621
6.5 MEDIUM

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of …

Aug 4, 2026
CVE-2026-47620
6.5 MEDIUM

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of …

Aug 4, 2026
CVE-2026-47619
6.6 MEDIUM

NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might …

Aug 4, 2026
CVE-2026-47487
4.4 MEDIUM

NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or …

Aug 4, 2026
CVE-2026-48121
6.7 MEDIUM

@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and below are vulnerable to NoSQL injection: checkpoint identifiers (thread_id, checkpoint_ns, checkpoint_id) …

Aug 4, 2026
CVE-2026-18785
5.3 MEDIUM

A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a manipulation can lead to use after …

Aug 4, 2026
CVE-2026-18784
5.3 MEDIUM

A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute of the file src/client/ua_client_highlevel.c. Performing a manipulation results in …

Aug 4, 2026
CVE-2026-18775
6.3 MEDIUM

A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/browser_tool.py of the component Browser …

Aug 4, 2026
CVE-2026-18774
6.3 MEDIUM

A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the component xAI Image …

Aug 4, 2026
CVE-2026-15920
6.1 MEDIUM

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating …

Aug 4, 2026
CVE-2026-15830
5.3 MEDIUM

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested …

Aug 4, 2026
CVE-2026-15337
5.3 MEDIUM

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, …

Aug 4, 2026
CVE-2026-24078
6.5 MEDIUM

Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.

Aug 4, 2026
CVE-2026-24077
6.5 MEDIUM

Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.

Aug 4, 2026
CVE-2026-24076
6.7 MEDIUM

Memory Corruption when processing registry values with incorrect types using a direct query method.

Aug 4, 2026
CVE-2026-18773
6.3 MEDIUM

A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component …

Aug 4, 2026
CVE-2026-67618
6.5 MEDIUM

marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operator API keys by embedding a malicious base_url in PEP-723 inline …

Aug 4, 2026
CVE-2026-67199
6.5 MEDIUM

Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a crafted expression containing …

Aug 4, 2026
CVE-2026-67196
5.4 MEDIUM

Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to inject arbitrary HTML and JavaScript by writing table cell …

Aug 4, 2026
CVE-2026-18766
6.3 MEDIUM

A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affects some unknown processing of the file /Applications/MAMP/htdocs/core-php-admin-panel-master/customers.php. Executing a manipulation of …

Aug 4, 2026
CVE-2026-70368
6.5 MEDIUM

A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A remote attacker with network access …

Aug 4, 2026
CVE-2026-70367
5.4 MEDIUM

A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to …

Aug 4, 2026
CVE-2026-63248
6.5 MEDIUM

In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a …

Aug 4, 2026
CVE-2026-18809
6.5 MEDIUM

Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153.0.3.

Aug 4, 2026
CVE-2026-18772
5.5 MEDIUM

Improper input validation vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads.

Aug 4, 2026
CVE-2026-14465
6.5 MEDIUM

Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay). This issue affects …

Aug 4, 2026
CVE-2026-14219
5.4 MEDIUM

URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Phishing. This issue affects HUMANIST …

Aug 4, 2026
CVE-2026-14202
5.3 MEDIUM

Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting. This issue affects HUMANIST Digital Human Resources: …

Aug 4, 2026
CVE-2026-14194
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Path …

Aug 4, 2026
CVE-2026-14192
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Stored XSS. …

Aug 4, 2026
CVE-2026-16548
5.4 MEDIUM

The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin before 1.8.2 does not validate the type, extension, …

Aug 4, 2026
CVE-2026-16547
5.9 MEDIUM

The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log entry being requested, nor …

Aug 4, 2026
CVE-2026-16546
4.3 MEDIUM

The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJAX actions, and does not verify that …

Aug 4, 2026
CVE-2026-16536
5.3 MEDIUM

The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side request, allowing unauthenticated attackers …

Aug 4, 2026
CVE-2026-16296
4.7 MEDIUM

The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect handler, passing a decoded request URI to …

Aug 4, 2026
CVE-2026-16295
4.3 MEDIUM

The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch paths, allowing any authenticated user such …

Aug 4, 2026
CVE-2026-16293
6.8 MEDIUM

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which could allow users …

Aug 4, 2026
CVE-2026-16069
6.8 MEDIUM

The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted through one of its AJAX actions before storing them and …

Aug 4, 2026
CVE-2026-16056
4.3 MEDIUM

The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down …

Aug 4, 2026
CVE-2026-16035
4.3 MEDIUM

The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the …

Aug 4, 2026
CVE-2026-15233
4.8 MEDIUM

The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML attributes on an administrative listing screen, allowing …

Aug 4, 2026
CVE-2026-14939
6.8 MEDIUM

The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing users with Contributor-level access …

Aug 4, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.