CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-18364
4.3 MEDIUM

The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on several of its AJAX actions, allowing users with a subscriber-level …

Sep 23, 2026
CVE-2026-16264
6.5 MEDIUM

The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to …

Sep 23, 2026
CVE-2025-15696
6.8 MEDIUM

The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rendering them back in the admin editor, allowing …

Sep 23, 2026
CVE-2026-96258
4.3 MEDIUM

A vulnerability has been found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722. This affects an unknown part of the file /forgotpasswd.html of …

Sep 23, 2026
CVE-2026-95957
4.3 MEDIUM

A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0. This issue affects the function prepend of the file student_signup.php of …

Sep 23, 2026
CVE-2026-95930
6.3 MEDIUM

A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the function UrlCheckTool.checkUrl of the component debugToolV2 API …

Sep 23, 2026
CVE-2026-95929
6.3 MEDIUM

A weakness has been identified in iFlytek astron-agent up to 1.0.7. Affected is an unknown function of the file console/backend/commons/src/main/resources/mapper/ChatBotMarketMapper.xml of the component getBotList API …

Sep 23, 2026
CVE-2026-95928
5.5 MEDIUM

A security flaw has been discovered in recommenders-team recommenders up to 1.2.1. This impacts the function pickle.load of the file recommenders/models/newsrec/io/mind_iterator.py of the component Dict …

Sep 23, 2026
CVE-2026-96273
5.5 MEDIUM

Ghidra before 12.1.4 fails to validate the TYPE_COL byte in OptionsDB.createUnregisteredOption(), causing an ArrayIndexOutOfBoundsException that leaves domain objects permanently locked. Attackers can craft a malicious …

Sep 23, 2026
CVE-2026-95897
5.5 MEDIUM

A security vulnerability has been detected in Dask up to 2026.8.0. This affects the function from_npy_stack of the file dask/array/core.py of the component Loader. Such …

Sep 23, 2026
CVE-2026-95868
6.3 MEDIUM

A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is the function mysqli_query of the file admin/display_menu.php of the …

Sep 23, 2026
CVE-2026-95833
6.3 MEDIUM

A weakness has been identified in itsourcecode Leave Management System 1.0. Impacted is an unknown function of the file /module/leavetype/index.php. This manipulation of the argument …

Sep 23, 2026
CVE-2026-95830
6.3 MEDIUM

A security flaw has been discovered in theRealSain Pixtream up to 866afd4f0cea812b918780fb74b67dccf8c4d6a0. This issue affects some unknown processing of the file /post_upload.php. The manipulation of …

Sep 23, 2026
CVE-2026-95829
6.3 MEDIUM

A vulnerability was identified in TDuckCloud tduck-platform up to 5.3. This vulnerability affects the function PaginationInnerInterceptor.concatOrderBy of the file tduck-api/src/main/java/com/tduck/cloud/api/config/MybatisPlusConfig.java of the component Pagination Inner …

Sep 23, 2026
CVE-2026-92930
6.2 MEDIUM

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administrator password-reset unlock-code design that lacks a per-device secret or other server-side cryptographic material. An …

Sep 23, 2026
CVE-2026-92929
5.3 MEDIUM

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an arbitrary client when determining the request source address. An unauthenticated …

Sep 23, 2026
CVE-2026-92928
6.5 MEDIUM

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential that cannot be changed, disabled, or rotated. …

Sep 23, 2026
CVE-2026-95828
4.3 MEDIUM

A vulnerability was determined in Mstfakts College-Management-System. This affects the function session_start of the file Front-end/server.php of the component Authentication. Executing a manipulation can lead …

Sep 22, 2026
CVE-2026-95820
6.3 MEDIUM

A vulnerability was found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php?section=admin1. Performing a manipulation …

Sep 22, 2026
CVE-2026-57576
6.5 MEDIUM

plone.app.dexterity is a content-type system for the Plone content management system, and plone.app.contenttypes provides Plone’s Dexterity-based content types. Plone.app.dexterity versions through 3.2.2, 4.0.0 through 4.1.2, …

Sep 22, 2026
CVE-2026-18170
6.5 MEDIUM

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to allocation of resources without …

Sep 22, 2026
CVE-2026-18161
4.3 MEDIUM

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to falsify transaction audit logs due to improper validation of a …

Sep 22, 2026
CVE-2026-18156
6.5 MEDIUM

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to bypass security controls by forging user identities due to improper …

Sep 22, 2026
CVE-2026-18153
5.4 MEDIUM

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the …

Sep 22, 2026
CVE-2026-18133
5.4 MEDIUM

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to modify server files due to path traversal.

Sep 22, 2026
CVE-2026-18132
6.5 MEDIUM

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to perform unauthorized payment mutation actions due to missing authorization.

Sep 22, 2026
CVE-2026-18124
6.5 MEDIUM

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information due to insufficiently protected credentials.

Sep 22, 2026
CVE-2026-18114
6.5 MEDIUM

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to read arbitrary files due to improper path canonicalization.

Sep 22, 2026
CVE-2026-17620
5.3 MEDIUM

IBM Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 through 4.0.6.0.0.6.0 Refresh (Operator 4.4.6+20260807.081800)4.0.7.04.0.8.04.0.9.04.0.10.0 Interim Fix 064 IBM Financial Transaction Manager transmits sensitive or security-critical …

Sep 22, 2026
CVE-2026-17465
6.5 MEDIUM

IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper enforcement of storage limits.

Sep 22, 2026
CVE-2026-16426
6.5 MEDIUM

IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, …

Sep 22, 2026
CVE-2026-15915
6.2 MEDIUM

IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images.

Sep 22, 2026
CVE-2025-36084
5.9 MEDIUM

IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Sep 22, 2026
CVE-2025-12767
5.3 MEDIUM

IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause …

Sep 22, 2026
CVE-2026-96260
6.5 MEDIUM

Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body size limit during CSRF validation …

Sep 22, 2026
CVE-2026-96259
5.5 MEDIUM

Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal-connection filter to OAuth endpoint requests, which …

Sep 22, 2026
CVE-2026-95815
6.3 MEDIUM

OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data. Attackers who obtain diagnostic archives …

Sep 22, 2026
CVE-2026-95813
6.1 MEDIUM

e621ng versions before 26.09.16 pass untrusted request parameters directly to Rails url_for in PaginatorComponent and controller navigation links, allowing attackers to redirect pagination and navigation …

Sep 22, 2026
CVE-2026-95812
6.1 MEDIUM

ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper function that fails to sanitize cat, sort, and time query parameters. …

Sep 22, 2026
CVE-2026-88020
6.1 MEDIUM

Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the …

Sep 22, 2026
CVE-2026-77425
4.3 MEDIUM

Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order passes attacker-controlled strategy IDs to unprotectedUpdateStrategiesSortOrder and updateSortOrder without verifying that the IDs …

Sep 22, 2026
CVE-2026-88341
5.5 MEDIUM

A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can provide a malicious file with an invalid …

Sep 22, 2026
CVE-2026-88339
5.5 MEDIUM

A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). The vulnerability occurs when cloning a PROTO default SFImage field with …

Sep 22, 2026
CVE-2026-83805
6.4 MEDIUM

Nautobot is a Network Source of Truth and Network Automation Platform. From 3.0.0 until 3.1.8, the generic ApprovalWorkflowStageResponse create endpoint does not enforce approver-group membership, …

Sep 22, 2026
CVE-2026-83801
5.4 MEDIUM

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.37 and 3.1.8, a user with extras.add_relationship or extras.change_relationship permission can store …

Sep 22, 2026
CVE-2026-79767
5.5 MEDIUM

Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142.6, 1.143.3, 1.144.2, and 1.145.0, the customverbauthorizer admission plugin's mustCheckProjectMembers …

Sep 22, 2026
CVE-2026-76717
5.3 MEDIUM

A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could …

Sep 22, 2026
CVE-2026-76716
5.3 MEDIUM

Multiple vulnerabilities exist in the Analytics and Location Engine (ALE) that may allow for unauthorized access or denial of service. An unauthenticated remote attacker could …

Sep 22, 2026
CVE-2026-65829
5.3 MEDIUM

MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 7.3.0 until 16.5.0, reading …

Sep 22, 2026
CVE-2026-91129
5.4 MEDIUM

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.2.3, the IPP integration automatically processed unauthenticated _ipp._tcp.local mDNS …

Sep 22, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.