CVE Database

48111+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-15358
7.5 HIGH

ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability.

Sep 23, 2026
CVE-2026-14913
8.8 HIGH

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vulnerability in Rule Management Search Reports.

Sep 23, 2026
CVE-2026-12370
7.6 HIGH

ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which …

Sep 23, 2026
CVE-2026-96455
8.8 HIGH

The Reachy Mini daemon exposes an HTTP API for managing the robot. Its app installation endpoint, POST /apps/install in src/reachy_mini/daemon/app/routers/apps.py, has no authentication. The handler's …

Sep 23, 2026
CVE-2026-96442
7.8 HIGH

A code execution flaw was found in Emacs, affecting versions prior to 31.2. The Flymake mode using language backends other than Lisp would execute arbitrary …

Sep 23, 2026
CVE-2026-96454
8.2 HIGH

Pake turns a website into a desktop application built on Tauri. Every application it generates inherits two settings from the upstream template, and together they …

Sep 23, 2026
CVE-2026-95627
7.7 HIGH

When a Tauri application uses the dialog plugin's file or folder picker, an attacker with JavaScript execution (XSS) can force the scope expansion to be …

Sep 23, 2026
CVE-2026-95626
8.3 HIGH

Tauri's Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero protection when an application includes data: or blob: in …

Sep 23, 2026
CVE-2026-94243
7.3 HIGH

A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects Apache Sling Security Bundle: before 1.3.2. Users are recommended to …

Sep 23, 2026
CVE-2026-93368
7.5 HIGH

The Rename wp-login.php to anything you want plugin for WordPress is vulnerable to time-based SQL Injection via 'log' (Username) Parameter in all versions up to, …

Sep 23, 2026
CVE-2026-42801
7.4 HIGH

NULL pointer dereference vulnerability in ASR Crane,Falcon on Linux (as_rrc module) allows Pointer Manipulation. This vulnerability is associated with program file 3g.mod/lib/src/urrsir.c.

Sep 23, 2026
CVE-2026-31377
7.5 HIGH

An Improper Authentication vulnerability in the Apache Doris Frontend (FE) meta service allows an unauthenticated remote attacker to access internal metadata service endpoints. The affected …

Sep 23, 2026
CVE-2026-15027
8.8 HIGH

CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce victims to visit a malicious web page and inject arbitrary …

Sep 23, 2026
CVE-2026-91818
7.8 HIGH

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, …

Sep 23, 2026
CVE-2026-91816
7.8 HIGH

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations. Reentrant annotation deletion triggered by embedded JavaScript can cause the application to access …

Sep 23, 2026
CVE-2026-91815
7.8 HIGH

Foxit PDF Editor/Reader does not perform sufficient verification of the JPEG2000 image metadata in the PDF file, which leads to out-of-bounds write in the heap …

Sep 23, 2026
CVE-2026-91813
8.8 HIGH

A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replaced between download and high-privilege extraction due to insufficient file locking …

Sep 23, 2026
CVE-2026-91812
7.9 HIGH

A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows man-in-the-middle attackers to bypass certificate validation and package integrity checks, potentially enabling arbitrary code execution with …

Sep 23, 2026
CVE-2026-91811
7.8 HIGH

A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s PRC parser due to insufficient validation of vertex indices in triangular fan texture meshes. Successful …

Sep 23, 2026
CVE-2026-91809
7.8 HIGH

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF form fields. Improper validation during field-name traversal may cause the application to access …

Sep 23, 2026
CVE-2026-91806
7.8 HIGH

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF form fields. Embedded JavaScript may access form-field references after the corresponding fields have been …

Sep 23, 2026
CVE-2026-91805
7.8 HIGH

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s PDF page-tree handling. A specially crafted PDF can trigger page-structure changes during rendering, causing the application to …

Sep 23, 2026
CVE-2026-91804
7.8 HIGH

A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s rendering of Circle annotations with malformed Cloudy appearance streams in specially crafted PDF files. Insufficient …

Sep 23, 2026
CVE-2026-91803
8.8 HIGH

A local privilege escalation vulnerability exists in the updater of Foxit PDF Editor/Reader due to unsafe loading of dynamic-link libraries from a user-writable directory during …

Sep 23, 2026
CVE-2026-91802
7.8 HIGH

A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s WebP image decoding due to improper handling of bitmap stride and target buffer formats. Successful …

Sep 23, 2026
CVE-2026-91801
7.8 HIGH

A path traversal vulnerability exists in Foxit PDF Editor/Reader's handling of embedded PDF resources. Insufficient validation of resource file paths may allow files to be …

Sep 23, 2026
CVE-2026-91800
8.8 HIGH

A local privilege escalation vulnerability exists in the installer of Foxit PDF Editor for macOS due to insufficient validation of a user-modifiable configuration value during …

Sep 23, 2026
CVE-2026-91799
7.8 HIGH

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of JavaScript array objects. A specially crafted PDF may cause the application to access a released …

Sep 23, 2026
CVE-2026-91798
8.8 HIGH

A local privilege escalation vulnerability exists in the update daemon of Foxit PDF Editor/Reader due to an insecure permission configuration that allows the configuration file …

Sep 23, 2026
CVE-2026-91797
7.8 HIGH

Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to be written to …

Sep 23, 2026
CVE-2026-91795
7.8 HIGH

Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files. This could leave an internal pointer in an …

Sep 23, 2026
CVE-2026-91794
7.8 HIGH

An out-of-bounds write vulnerability exists in the PDF rendering process of Foxit PDF Editor/Reader due to insufficient consistency and boundary validation when processing malformed color …

Sep 23, 2026
CVE-2026-91793
7.8 HIGH

When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attributes containing malformed font data. During subsequent annotation appearance reconstruction, …

Sep 23, 2026
CVE-2026-91792
7.8 HIGH

When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layout operations through page- and annotation-related JavaScript actions. This can cause …

Sep 23, 2026
CVE-2026-91791
7.8 HIGH

When processing a specially crafted PDF file, Foxit PDF Editor/Reader may encounter a reentrant execution condition involving JavaScript triggered by page-visibility events. This can cause …

Sep 23, 2026
CVE-2026-91790
7.8 HIGH

When rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects whose optional content attributes are malformed. As a result, the …

Sep 23, 2026
CVE-2026-91789
7.8 HIGH

Foxit PDF Editor/Reader’s U3D/GIF texture decoding path contained insufficient validation of image dimensions and related size information. Under certain conditions, this could lead to an …

Sep 23, 2026
CVE-2026-93508
8.1 HIGH

The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and …

Sep 23, 2026
CVE-2026-86608
8.2 HIGH

The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor does it bound what …

Sep 23, 2026
CVE-2026-19438
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Mint Workbench I. This issue affects Mint Workbench I: through 5876.

Sep 23, 2026
CVE-2026-14321
8.2 HIGH

The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limiting and banning, allowing unauthenticated …

Sep 23, 2026
CVE-2022-4997
8.6 HIGH

The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to …

Sep 23, 2026
CVE-2026-91777
7.5 HIGH

Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are …

Sep 23, 2026
CVE-2026-91776
7.5 HIGH

TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use …

Sep 23, 2026
CVE-2026-89425
7.5 HIGH

UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has …

Sep 23, 2026
CVE-2026-95927
7.3 HIGH

A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/pretest/exam-delete.php. Such manipulation of the argument …

Sep 23, 2026
CVE-2026-95926
7.3 HIGH

A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admins/assessments/pretest/btn_functions.php?action=update. This manipulation of …

Sep 23, 2026
CVE-2026-96272
7.5 HIGH

ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the query parameter is passed unsanitized into SQL WHERE …

Sep 23, 2026
CVE-2026-96271
7.1 HIGH

Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links for albums owned by …

Sep 23, 2026
CVE-2026-95925
7.3 HIGH

A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=update. The manipulation of …

Sep 23, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.