CVE Database

48111+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-95924
7.3 HIGH

A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=add. The manipulation of the …

Sep 23, 2026
CVE-2026-94367
7.2 HIGH

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated administrator can supply crafted backup-area configuration input …

Sep 23, 2026
CVE-2026-61685
7.5 HIGH

ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list endpoints build TypeORM `QueryBuilder` conditions using unsanitized HTTP query parameter …

Sep 22, 2026
CVE-2026-18176
7.4 HIGH

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.

Sep 22, 2026
CVE-2026-18172
7.4 HIGH

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity …

Sep 22, 2026
CVE-2026-95819
7.3 HIGH

A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this vulnerability is an unknown functionality of the file login.php. Such manipulation …

Sep 22, 2026
CVE-2026-18154
8.0 HIGH

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to the use of a hard-coded or …

Sep 22, 2026
CVE-2026-18152
7.4 HIGH

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to forge validly-signed messages due to improper verification of cryptographic signatures.

Sep 22, 2026
CVE-2026-18137
8.1 HIGH

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary ESQL commands due to improper neutralization of special elements …

Sep 22, 2026
CVE-2026-18134
7.5 HIGH

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.

Sep 22, 2026
CVE-2026-18131
8.2 HIGH

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary JavaScript in an authenticated user's browser due to improper …

Sep 22, 2026
CVE-2026-18123
7.6 HIGH

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to the improper use of …

Sep 22, 2026
CVE-2026-18095
8.5 HIGH

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow.

Sep 22, 2026
CVE-2026-18074
8.2 HIGH

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper authentication and missing authorization.

Sep 22, 2026
CVE-2026-18066
7.9 HIGH

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and trigger unauthorized actions due to server-side request …

Sep 22, 2026
CVE-2026-17647
8.8 HIGH

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to execute arbitrary commands due to the inclusion of functionality from an …

Sep 22, 2026
CVE-2026-17646
8.5 HIGH

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper restriction of XML external …

Sep 22, 2026
CVE-2026-17644
8.8 HIGH

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to gain unauthorized access to sensitive information and modify transaction data due …

Sep 22, 2026
CVE-2026-17643
8.8 HIGH

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and perform unauthorized actions due to insufficiently protected …

Sep 22, 2026
CVE-2026-17637
8.8 HIGH

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network attacker to execute arbitrary code due to deserialization of untrusted data.

Sep 22, 2026
CVE-2026-17636
8.8 HIGH

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to improper validation of a specified …

Sep 22, 2026
CVE-2026-17618
7.3 HIGH

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of …

Sep 22, 2026
CVE-2026-17102
8.8 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements …

Sep 22, 2026
CVE-2026-16672
8.8 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements …

Sep 22, 2026
CVE-2026-16469
8.8 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 px-runtime could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special …

Sep 22, 2026
CVE-2026-16468
8.8 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to OS command injection.

Sep 22, 2026
CVE-2026-95814
8.1 HIGH

Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment …

Sep 22, 2026
CVE-2026-94450
7.5 HIGH

Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial of service …

Sep 22, 2026
CVE-2026-91018
8.8 HIGH

lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim …

Sep 22, 2026
CVE-2026-67615
8.8 HIGH

openEQUELLA before 2026.1.0 contains an authenticated remote code execution vulnerability that allows any authenticated non-guest user to execute arbitrary code by exploiting Java deserialization in …

Sep 22, 2026
CVE-2026-94574
7.8 HIGH

A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\msys64) that is writable …

Sep 22, 2026
CVE-2026-89281
8.4 HIGH

The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability within openssl.cnf path that can allow local code execution.

Sep 22, 2026
CVE-2026-88419
8.8 HIGH

An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=thumbUpload) of WuzhiCMS 5.0.0 allows an authenticated low-privileged member to upload a …

Sep 22, 2026
CVE-2026-88418
8.8 HIGH

CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-changing admin request, and it does not send …

Sep 22, 2026
CVE-2026-88345
7.5 HIGH

An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers schema ends with an unterminated quotation mark, the C-string …

Sep 22, 2026
CVE-2026-88344
7.5 HIGH

An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers schema buffer ends with a digit, the integer digit-scan …

Sep 22, 2026
CVE-2026-88340
7.6 HIGH

An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of external-variable …

Sep 22, 2026
CVE-2026-77322
7.5 HIGH

SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go creates a wsutil.Reader without setting MaxFrameSize, allowing …

Sep 22, 2026
CVE-2026-76715
7.1 HIGH

A vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable to a man-in-the-middle (MitM) attack. Successful exploitation of this vulnerability could …

Sep 22, 2026
CVE-2026-76714
7.2 HIGH

Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could …

Sep 22, 2026
CVE-2026-76713
7.2 HIGH

A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an authenticated remote attacker …

Sep 22, 2026
CVE-2026-76712
7.3 HIGH

A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information disclosure, or denial of service. An unauthenticated remote …

Sep 22, 2026
CVE-2026-76711
7.5 HIGH

A vulnerability exists in an Analytics and Location Engine (ALE) component where the impacted process improperly processes incoming socket connections. An unauthenticated remote attacker could …

Sep 22, 2026
CVE-2026-76710
7.5 HIGH

A vulnerability exists in the Analytics and Location Engine (ALE) management interface that may allow for the disclosure of sensitive information. An unauthenticated remote attacker …

Sep 22, 2026
CVE-2026-63104
8.1 HIGH

Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated workspace members with viewer or member roles to delete and modify tasks …

Sep 22, 2026
CVE-2026-62985
7.5 HIGH

request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Prior to 3.2.1, RequestFilteringHttpAgent and RequestFilteringHttpsAgent synchronously threw from createConnection when rejecting a …

Sep 22, 2026
CVE-2026-61570
7.5 HIGH

MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 5.5.5 until 16.4.1, MerlinReader …

Sep 22, 2026
CVE-2026-59991
7.5 HIGH

psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to 1.17.4, PSDImage.composite() and PSDImage.numpy() allocated output buffers from attacker-controlled PSD header …

Sep 22, 2026
CVE-2026-58268
7.5 HIGH

SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.1, ParserStream.parseSingle in sip/parser_stream.go allocates a SIP body buffer from the …

Sep 22, 2026
CVE-2026-28325
8.8 HIGH

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is …

Sep 22, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.