CVE Database

48111+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-58007
8.1 HIGH

Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through …

Sep 24, 2026
CVE-2026-58006
8.1 HIGH

Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through …

Sep 24, 2026
CVE-2026-58005
8.1 HIGH

Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0.

Sep 24, 2026
CVE-2026-58004
8.1 HIGH

Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0.

Sep 24, 2026
CVE-2026-56736
8.2 HIGH

phpMyFAQ is an open source FAQ web application. A stored cross-site scripting (XSS) vulnerability in versions prior to 4.2.0-alpha allows any unauthenticated user (or low-privileged …

Sep 24, 2026
CVE-2026-51997
8.8 HIGH

An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functions

Sep 24, 2026
CVE-2026-51995
7.5 HIGH

An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive information via the src/lib/authorization-server-metadata.ts, src/lib/utils.ts components

Sep 24, 2026
CVE-2026-13467
8.1 HIGH

Out-of-bounds write vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.

Sep 24, 2026
CVE-2026-13466
8.1 HIGH

Incorrect calculation of buffer size vulnerability in Altera Trusted Firmware on HPS allows Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0.

Sep 24, 2026
CVE-2026-13465
8.1 HIGH

Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through …

Sep 24, 2026
CVE-2026-97059
8.2 HIGH

DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames. …

Sep 24, 2026
CVE-2026-97057
7.5 HIGH

redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively …

Sep 24, 2026
CVE-2026-95521
7.8 HIGH

A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct …

Sep 24, 2026
CVE-2026-95519
7.8 HIGH

A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q …

Sep 24, 2026
CVE-2026-97182
7.3 HIGH

A security vulnerability has been detected in halo-dev Halo up to 2.25.4/2.26.1. Affected is an unknown function of the file application/src/main/java/run/halo/app/content/comment/ReplyNotificationSubscriptionHelper.java of the component SpEL …

Sep 24, 2026
CVE-2026-88907
7.4 HIGH

Incorrect Authorization vulnerability in TÜBİTAK ULAKBİM UlakPDF allows Authentication Bypass. This issue affects UlakPDF: through 09092026.

Sep 24, 2026
CVE-2026-57590
8.1 HIGH

A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has …

Sep 24, 2026
CVE-2026-97185
7.8 HIGH

A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into …

Sep 24, 2026
CVE-2026-85682
8.8 HIGH

The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the …

Sep 24, 2026
CVE-2026-78311
8.8 HIGH

SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

Sep 24, 2026
CVE-2026-78309
8.8 HIGH

SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

Sep 24, 2026
CVE-2026-77193
7.5 HIGH

The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` …

Sep 24, 2026
CVE-2026-88843
7.2 HIGH

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings before using it to build a template path, …

Sep 24, 2026
CVE-2026-80513
7.5 HIGH

The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated …

Sep 24, 2026
CVE-2026-96898
7.3 HIGH

A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this vulnerability is an unknown functionality of the file config/ueditor.php of the component …

Sep 24, 2026
CVE-2026-97055
8.1 HIGH

SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and Config.Validate() …

Sep 24, 2026
CVE-2026-96803
7.3 HIGH

A vulnerability was identified in java110 MicroCommunity up to 2.0. Affected is the function QueryServiceSMOImpl.fallBack of the file BusinessApi.java of the component fallBack API Endpoint. …

Sep 24, 2026
CVE-2026-96762
7.3 HIGH

A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component RPC Path Handler. This manipulation of the …

Sep 24, 2026
CVE-2026-96751
7.3 HIGH

A vulnerability has been found in pmTicket Project-Management-Software up to 078fa56a782490c5059a0814f84df27984f4d7e2. This affects the function setSync of the file /ajax/add_project.php. Such manipulation of the argument …

Sep 24, 2026
CVE-2026-92470
7.7 HIGH

GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain …

Sep 24, 2026
CVE-2026-70125
8.8 HIGH

Microsoft Office Outlook Remote Code Execution Vulnerability

Sep 23, 2026
CVE-2026-96604
7.3 HIGH

A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0. This affects the function strip_data of the file engine/modules/search.php of the component Search Module. …

Sep 23, 2026
CVE-2026-96603
7.3 HIGH

A vulnerability has been found in Abdurrab5 online-makeup-store. Affected is the function confirm_logged_in/confirm_user of the file functions.php of the component Admin Handler. Such manipulation of …

Sep 23, 2026
CVE-2026-96602
7.3 HIGH

A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file customerSignin.php of the component Customer Login Handler. This manipulation …

Sep 23, 2026
CVE-2026-96601
7.3 HIGH

A vulnerability was detected in Abdurrab5 online-makeup-store. This affects an unknown function of the file index.php of the component Admin Login Handler. The manipulation of …

Sep 23, 2026
CVE-2026-86583
8.8 HIGH

The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the …

Sep 23, 2026
CVE-2026-81537
8.8 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to OS command injection.

Sep 23, 2026
CVE-2026-81536
7.7 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) …

Sep 23, 2026
CVE-2026-81208
7.7 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. An …

Sep 23, 2026
CVE-2026-80423
8.8 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets …

Sep 23, 2026
CVE-2026-75887
7.5 HIGH

A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters …

Sep 23, 2026
CVE-2026-19125
8.1 HIGH

The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5. This is due to …

Sep 23, 2026
CVE-2026-96556
7.3 HIGH

A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function addcashier of the file AddCashierCode.php. Executing a manipulation of the …

Sep 23, 2026
CVE-2026-80425
8.8 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements …

Sep 23, 2026
CVE-2026-80412
8.8 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper escaping of connector property …

Sep 23, 2026
CVE-2026-80379
8.8 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements …

Sep 23, 2026
CVE-2026-75886
7.2 HIGH

A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandler, which lacks proper authentication, and the forwarding of …

Sep 23, 2026
CVE-2026-6935
7.8 HIGH

IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker …

Sep 23, 2026
CVE-2026-6794
7.8 HIGH

IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management. A local attacker can exploit this flaw to …

Sep 23, 2026
CVE-2026-96889
7.8 HIGH

A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. …

Sep 23, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.