CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-97649
4.7 MEDIUM

A flaw has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this vulnerability is an unknown functionality of the file example_lite.sql. Executing a …

Sep 25, 2026
CVE-2026-97648
4.3 MEDIUM

A vulnerability was detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function. Performing a manipulation results in cross-site request forgery. It is …

Sep 25, 2026
CVE-2026-97647
5.3 MEDIUM

A security vulnerability has been detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. This impacts an unknown function of the file user/editLog.php. Such manipulation of the …

Sep 25, 2026
CVE-2026-95811
6.5 MEDIUM

Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass …

Sep 25, 2026
CVE-2026-97636
6.5 MEDIUM

Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author …

Sep 24, 2026
CVE-2026-97368
6.3 MEDIUM

A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInfo of the file blade-service/blade-system/src/main/java/org/springblade/system/service/impl/UserServiceImpl.java of the component user-auth-info Endpoint. …

Sep 24, 2026
CVE-2026-97366
6.3 MEDIUM

A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function openDevTools of the file electron/window.js of the …

Sep 24, 2026
CVE-2026-88387
5.5 MEDIUM

LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF tag 0x00fe (NewSubfileType). A specially crafted RAW, TIFF, or DNG file can …

Sep 24, 2026
CVE-2026-88386
5.5 MEDIUM

libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A specially crafted WAV file can cause the function to …

Sep 24, 2026
CVE-2026-87118
5.7 MEDIUM

The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality. An authenticated attacker with adjacent network access …

Sep 24, 2026
CVE-2026-84403
6.2 MEDIUM

The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. …

Sep 24, 2026
CVE-2026-82716
4.6 MEDIUM

The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process. These logs remain accessible …

Sep 24, 2026
CVE-2026-82708
6.5 MEDIUM

The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could …

Sep 24, 2026
CVE-2026-82585
6.5 MEDIUM

The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi …

Sep 24, 2026
CVE-2026-79959
6.8 MEDIUM

The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware …

Sep 24, 2026
CVE-2026-75558
5.3 MEDIUM

The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who …

Sep 24, 2026
CVE-2026-97365
6.3 MEDIUM

A vulnerability was determined in chonkie-inc littrs 0.6.1/0.6.2. Impacted is the function Sandbox::mount of the file crates/littrs/src/lib.rs. Executing a manipulation of the argument relative can …

Sep 24, 2026
CVE-2026-97325
4.3 MEDIUM

A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability is the function validOAuthClientFromCache of the file yudao-module-system/src/main/java/cn/iocoder/yudao/module/system/service/oauth2/OAuth2ClientServiceImpl.java of …

Sep 24, 2026
CVE-2026-93290
5.5 MEDIUM

Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data.

Sep 24, 2026
CVE-2026-88956
6.8 MEDIUM

The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface. The affected account does not …

Sep 24, 2026
CVE-2026-88761
5.3 MEDIUM

The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product. An unauthenticated …

Sep 24, 2026
CVE-2026-48543
5.4 MEDIUM

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting …

Sep 24, 2026
CVE-2026-48542
5.4 MEDIUM

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting …

Sep 24, 2026
CVE-2026-48541
5.4 MEDIUM

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting …

Sep 24, 2026
CVE-2026-48540
5.4 MEDIUM

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting …

Sep 24, 2026
CVE-2026-97323
6.3 MEDIUM

A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOriginalFilename of the file yudao-module-mp/src/main/java/cn/iocoder/yudao/module/mp/service/material/MpMaterialServiceImpl.java of the component File Upload. Executing …

Sep 24, 2026
CVE-2026-97322
4.3 MEDIUM

A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the file yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/file/FileController.java of the component File Upload. Performing …

Sep 24, 2026
CVE-2026-97321
6.3 MEDIUM

A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function GoViewDataServiceImpl.getDataBySQL of the file yudao-module-report/src/main/java/cn/iocoder/yudao/module/report/service/goview/GoViewDataServiceImpl.java of the component …

Sep 24, 2026
CVE-2026-97320
6.3 MEDIUM

A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowledgeDocumentServiceImpl.readUrl of the file AiKnowledgeDocumentServiceImpl.java of the component …

Sep 24, 2026
CVE-2026-96748
6.5 MEDIUM

PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a …

Sep 24, 2026
CVE-2026-96747
5.0 MEDIUM

The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix …

Sep 24, 2026
CVE-2026-85738
6.3 MEDIUM

TREK is a collaborative travel planner. Prior to 3.4.0, the checkSsrf logic in server/src/utils/ssrfGuard.ts does not recognize NAT64, 6to4, or Teredo IPv6 transition addresses that …

Sep 24, 2026
CVE-2026-77321
4.3 MEDIUM

TREK is a collaborative travel planner. Prior to 3.3.0, the get_trip_summary tool in server/src/mcp/tools/trips.ts is registered for scoped OAuth MCP tokens without requiring trips:read and …

Sep 24, 2026
CVE-2026-77320
5.3 MEDIUM

TREK is a collaborative travel planner. Prior to 3.3.0, getSharedTripData in server/src/services/shareService.ts returns days, assignments, dayNotes, and places through GET /api/shared/:token even when the trip …

Sep 24, 2026
CVE-2026-65827
6.5 MEDIUM

Docmost is open-source collaborative wiki and documentation software. From 0.21.0 until 0.95.0, any authenticated workspace member with edit rights to a space can upload an …

Sep 24, 2026
CVE-2026-62286
4.3 MEDIUM

Dozzle is a realtime log viewer for docker containers. Prior to 10.6.7, streamEvents in internal/web/events.go applies a restricted user's label filter to container lists but …

Sep 24, 2026
CVE-2026-56792
4.4 MEDIUM

Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this …

Sep 24, 2026
CVE-2026-52853
5.2 MEDIUM

Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace ADMIN can use the workspace invitation flow to invite an external …

Sep 24, 2026
CVE-2026-52850
4.3 MEDIUM

Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace member who does not belong to a private space can call …

Sep 24, 2026
CVE-2026-48073
4.3 MEDIUM

Docmost is open-source collaborative wiki and documentation software. From 0.70.0 until 0.80.1, a low-privileged authenticated user who can edit an exportable page can embed a …

Sep 24, 2026
CVE-2026-48072
5.3 MEDIUM

Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, the public avatar and logo image endpoint accepts attacker-controlled fileName path segments and resolves …

Sep 24, 2026
CVE-2026-97232
6.3 MEDIUM

A vulnerability was determined in volotat Anagnorisis up to 0.4.2. Affected by this vulnerability is the function get_file_content/save_file_content/move_files/start_streaming of the file page.html. This manipulation causes …

Sep 24, 2026
CVE-2026-93405
6.1 MEDIUM

Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markdown, DOCX, and XLSX attachments with Snarkdown, Mammoth, and SheetJS …

Sep 24, 2026
CVE-2026-91121
5.0 MEDIUM

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, attacker-controlled upload filenames used in chat message excerpts were rendered as unescaped …

Sep 24, 2026
CVE-2026-91120
5.4 MEDIUM

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, provider-controlled video titles in lazy video embeds could be reparsed as HTML …

Sep 24, 2026
CVE-2026-91119
6.4 MEDIUM

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the topic small-action and nested-activity-log components interpolated the free-form action_code_who value into …

Sep 24, 2026
CVE-2026-81508
4.3 MEDIUM

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.5, 6.0.1, and 6.1, the BlueDroid A2DP sink function btc_a2dp_sink_handle_inc_media() reads a timestamp field …

Sep 24, 2026
CVE-2026-61811
6.5 MEDIUM

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.8.0 until 4.14.7, the _getattributes() function in …

Sep 24, 2026
CVE-2026-61784
6.1 MEDIUM

xhtml-purifier is a Node.js library to take in raw/unknown/untrusted HTML and output cleaned, purified, trusted HTML. Versions prior to 0.4.3 do not HTML-entity-encode attribute values …

Sep 24, 2026
CVE-2026-57179
4.2 MEDIUM

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it …

Sep 24, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.