CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-56678
6.4 MEDIUM

9Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key builds an upstream URL using a user-controlled …

Jul 15, 2026
CVE-2026-55608
4.2 MEDIUM

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.57.4, multi-tenant HTTP mode with ENABLE_MULTI_TENANT=true …

Jul 15, 2026
CVE-2026-55410
6.7 MEDIUM

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.1.19, NocoBase @nocobase/plugin-backups restored PostgreSQL backups by interpolating the database.schema …

Jul 15, 2026
CVE-2026-55399
4.3 MEDIUM

CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with valid credentials to the Secure Access tunnel can create …

Jul 15, 2026
CVE-2026-52888
6.8 MEDIUM

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.59 and earlier, NocoBase @nocobase/plugin-collection-sql used the checkSQL() function in packages/plugins/@nocobase/plugin-collection-sql/src/server/utils.ts …

Jul 15, 2026
CVE-2026-38753
4.9 MEDIUM

A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

Jul 15, 2026
CVE-2026-33684
5.3 MEDIUM

WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded permission parameters in signUp API, which allows …

Jul 15, 2026
CVE-2026-33445
5.9 MEDIUM

CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel …

Jul 15, 2026
CVE-2026-56743
5.4 MEDIUM

Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors …

Jul 15, 2026
CVE-2026-56742
5.9 MEDIUM

Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create …

Jul 15, 2026
CVE-2026-45737
6.3 MEDIUM

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expose Kubernetes Secret …

Jul 15, 2026
CVE-2026-40953
4.4 MEDIUM

CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and administrator permissions can …

Jul 15, 2026
CVE-2026-33443
5.9 MEDIUM

CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel …

Jul 15, 2026
CVE-2026-62947
4.9 MEDIUM

OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus …

Jul 15, 2026
CVE-2026-62355
5.4 MEDIUM

TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Reader admin_user on a TDengine Cloud DB …

Jul 15, 2026
CVE-2026-62353
5.4 MEDIUM

TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailing backslash in a SQL string …

Jul 15, 2026
CVE-2026-62348
5.4 MEDIUM

TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allowed an authenticated low-privilege SQL user to run KILL …

Jul 15, 2026
CVE-2026-26032
5.4 MEDIUM

The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repackaging …

Jul 15, 2026
CVE-2026-15746
6.5 MEDIUM

Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including …

Jul 15, 2026
CVE-2026-61643
5.9 MEDIUM

FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can save a workflow node that points to another user's …

Jul 15, 2026
CVE-2026-56087
6.1 MEDIUM

Dell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism Failure vulnerability. An attacker with physical access could potentially exploit this vulnerability, leading to …

Jul 15, 2026
CVE-2026-20298
5.3 MEDIUM

In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.3.2512.15, 10.2.2510.18, and 10.1.2507.24, a low-privileged user …

Jul 15, 2026
CVE-2026-14961
6.2 MEDIUM

Pegatron `Tdelo64.sys` exposes a privileged device interface, `\\.\TdeIo`, that fails to properly restrict access to sensitive IOCTL functionality. The driver's IOCTL dispatcher does not validate …

Jul 15, 2026
CVE-2026-49997
5.4 MEDIUM

SurrealDB is a scalable, distributed, collaborative, document-graph database for the realtime web. Prior to 3.1.0, Document::purge_edges in surrealdb/core/src/doc/delete.rs automatically removed graph edge records with permissions …

Jul 15, 2026
CVE-2026-20146
5.5 MEDIUM

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal …

Jul 15, 2026
CVE-2026-1563
4.8 MEDIUM

Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user …

Jul 15, 2026
CVE-2026-1562
4.8 MEDIUM

Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user …

Jul 15, 2026
CVE-2025-32781
6.5 MEDIUM

Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions …

Jul 15, 2026
CVE-2026-62843
6.8 MEDIUM

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's …

Jul 15, 2026
CVE-2026-47160
5.8 MEDIUM

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/{domain}/icon.png endpoint used src/http_client.rs checks including should_block_address() and post_resolve() that missed decimal, hexadecimal, …

Jul 15, 2026
CVE-2026-41580
6.1 MEDIUM

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, Stirling-PDF's /get-info-on-pdf endpoint rendered PDF Title and Author …

Jul 15, 2026
CVE-2026-60062
6.4 MEDIUM

The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. The …

Jul 15, 2026
CVE-2026-56434
6.5 MEDIUM

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering …

Jul 15, 2026
CVE-2026-54562
6.5 MEDIUM

Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, Cloudreve's remote download workflow accepts user-supplied URLs at POST /api/v4/workflow/download and passes them …

Jul 15, 2026
CVE-2026-52865
6.5 MEDIUM

When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause …

Jul 15, 2026
CVE-2026-33213
6.1 MEDIUM

Redash is a package for data visualization and sharing. From 5.0.2 to 26.3.0, the get_next_path() function in Redash's authentication module stripped the scheme and netloc …

Jul 15, 2026
CVE-2026-59838
5.9 MEDIUM

A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.2.0 through …

Jul 15, 2026
CVE-2026-58559
6.5 MEDIUM

DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availability.

Jul 15, 2026
CVE-2026-58557
4.8 MEDIUM

Design defect vulnerability in Expedition mode. Impact: Successful exploitation of this vulnerability may affect availability.

Jul 15, 2026
CVE-2026-58556
5.1 MEDIUM

Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect availability.

Jul 15, 2026
CVE-2026-58555
6.6 MEDIUM

Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect availability.

Jul 15, 2026
CVE-2026-58554
6.6 MEDIUM

Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jul 15, 2026
CVE-2026-58553
4.0 MEDIUM

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jul 15, 2026
CVE-2026-58552
5.1 MEDIUM

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jul 15, 2026
CVE-2026-58551
5.1 MEDIUM

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jul 15, 2026
CVE-2026-58550
4.0 MEDIUM

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jul 15, 2026
CVE-2026-58549
4.0 MEDIUM

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jul 15, 2026
CVE-2026-15779
6.1 MEDIUM

A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a …

Jul 15, 2026
CVE-2026-61453
6.1 MEDIUM

Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detectXss()) runs on raw page content before Twig processing. When Twig …

Jul 15, 2026
CVE-2026-61452
5.3 MEDIUM

The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where JWT access tokens are issued without a jti (JWT ID) claim …

Jul 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.