CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-44452
5.9 MEDIUM

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or …

Jul 16, 2026
CVE-2026-44434
5.3 MEDIUM

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit dccf5d4, Quicly was vulnerable to stateless …

Jul 16, 2026
CVE-2026-44433
5.3 MEDIUM

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, an adversarial peer could send …

Jul 16, 2026
CVE-2026-62826
4.6 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jul 16, 2026
CVE-2026-58643
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.

Jul 16, 2026
CVE-2026-14782
4.9 MEDIUM

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up …

Jul 16, 2026
CVE-2026-13713
6.2 MEDIUM

YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack. In the …

Jul 16, 2026
CVE-2026-61378
5.5 MEDIUM

A divide-by-zero vulnerability in the Productivity Suite allows a local attacker to cause a division by zero leading to a system crash.

Jul 16, 2026
CVE-2026-60073
5.9 MEDIUM

An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB device. This can lead …

Jul 16, 2026
CVE-2026-57896
6.1 MEDIUM

An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCTL request. This could …

Jul 16, 2026
CVE-2026-36425
6.5 MEDIUM

An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send process termination …

Jul 16, 2026
CVE-2026-33731
6.5 MEDIUM

WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/AuthorizeNet/webhook.php contains a signature verification bypass that …

Jul 16, 2026
CVE-2026-11889
6.5 MEDIUM

SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation attack that could allow an authorized attacker to …

Jul 16, 2026
CVE-2024-32387
5.7 MEDIUM

An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the community string component.

Jul 16, 2026
CVE-2024-32385
4.3 MEDIUM

An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via a boardID and revisionID components

Jul 16, 2026
CVE-2026-63397
6.4 MEDIUM

remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL schema that is passed to genql to inject arbitrary JavaScript or TypeScript. …

Jul 16, 2026
CVE-2026-62299
5.3 MEDIUM

CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an optional revert flag, and …

Jul 16, 2026
CVE-2026-61718
5.4 MEDIUM

bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb web UI BiscuitMiddleware authorization bypass list included the /cache/ …

Jul 16, 2026
CVE-2026-60140
6.1 MEDIUM

An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCTL request. This can …

Jul 16, 2026
CVE-2026-47089
4.3 MEDIUM

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user could call …

Jul 16, 2026
CVE-2026-47085
4.0 MEDIUM

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a …

Jul 16, 2026
CVE-2026-47084
6.5 MEDIUM

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An authenticated but non-admin user could invoke the …

Jul 16, 2026
CVE-2026-47083
4.3 MEDIUM

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated …

Jul 16, 2026
CVE-2026-47082
5.4 MEDIUM

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-mailbox ACL. A user whose vacation Sieve script …

Jul 16, 2026
CVE-2026-46514
6.5 MEDIUM

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_reset_password in Tools/ResetPassword.php:48-53 returned a plaintext password and fm_add_extension in Tools/AddExtension.php:172 returned …

Jul 16, 2026
CVE-2026-46404
6.8 MEDIUM

BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly restrict access to site local and link local addresses. …

Jul 16, 2026
CVE-2026-46378
6.2 MEDIUM

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the selector lexer matchRegexPattern closure in (*Tokenizer).parseCurRune …

Jul 16, 2026
CVE-2026-46377
6.2 MEDIUM

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the escape sequence handler in (*Tokenizer).parseCurRune in …

Jul 16, 2026
CVE-2026-46338
4.3 MEDIUM

PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.snippets uses a string-prefix containment check in SnippetPreprocessor.get_snippet_path() in …

Jul 16, 2026
CVE-2026-46341
6.1 MEDIUM

The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior …

Jul 16, 2026
CVE-2026-44968
6.3 MEDIUM

dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_command() in src/dbt_mcp/dbt_cli/tools.py appended unsanitized node_selection and resource_type values to the …

Jul 16, 2026
CVE-2026-15945
4.3 MEDIUM

A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated …

Jul 16, 2026
CVE-2026-15737
5.7 MEDIUM

AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform. Unintended …

Jul 16, 2026
CVE-2026-6511
5.5 MEDIUM

During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that could allow a local authenticated …

Jul 16, 2026
CVE-2026-55548
4.3 MEDIUM

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges when a request …

Jul 16, 2026
CVE-2026-50012
5.5 MEDIUM

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in …

Jul 16, 2026
CVE-2026-47729
6.5 MEDIUM

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway …

Jul 16, 2026
CVE-2026-45795
5.3 MEDIUM

The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server accepts unsigned JWE request objects because JwtAuthorizationRequest skips inner …

Jul 16, 2026
CVE-2026-45612
5.5 MEDIUM

rz-libdemangle is a Rizin library for demangling symbols. Prior to 6bf56d3, the Rust demangler in src/rust/rust_v0.c can perform an out-of-bounds read when the demangler structure …

Jul 16, 2026
CVE-2026-44596
6.5 MEDIUM

Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, …

Jul 16, 2026
CVE-2026-44595
4.3 MEDIUM

Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required …

Jul 16, 2026
CVE-2026-10590
4.4 MEDIUM

A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrarily trigger a System Management Interrupt handler.

Jul 16, 2026
CVE-2026-10589
6.0 MEDIUM

A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.

Jul 16, 2026
CVE-2026-10588
4.4 MEDIUM

A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.

Jul 16, 2026
CVE-2026-10587
6.0 MEDIUM

A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode.

Jul 16, 2026
CVE-2025-45870
6.5 MEDIUM

LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated user to exploit path …

Jul 16, 2026
CVE-2026-63082
5.4 MEDIUM

Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers with Agent-level privileges to manipulate the …

Jul 16, 2026
CVE-2026-63081
5.4 MEDIUM

Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious …

Jul 16, 2026
CVE-2026-57205
4.3 MEDIUM

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.203, the authenticated GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> …

Jul 16, 2026
CVE-2026-55440
6.5 MEDIUM

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/server/ws/handler.py called get_or_create_session in ufo/server/services/session_manager.py without owner_client_id, …

Jul 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.