CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-61449
6.5 MEDIUM

Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in 2.0.1 sums the uncompressed size declared in each entry's …

Jul 15, 2026
CVE-2026-61440
6.5 MEDIUM

PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remove …

Jul 15, 2026
CVE-2026-60087
6.1 MEDIUM

PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals for subsequent calls with arbitrary arguments. Attackers can …

Jul 15, 2026
CVE-2026-59259
6.5 MEDIUM

n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between the static validation check …

Jul 15, 2026
CVE-2026-56353
4.8 MEDIUM

n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, …

Jul 15, 2026
CVE-2026-56352
6.4 MEDIUM

n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile source option, which reads workflow files from disk without the …

Jul 15, 2026
CVE-2026-49501
6.7 MEDIUM

Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vulnerability. A high privileged attacker with local access …

Jul 15, 2026
CVE-2026-11580
5.5 MEDIUM

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, …

Jul 15, 2026
CVE-2026-11579
5.3 MEDIUM

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing …

Jul 15, 2026
CVE-2026-36035
6.5 MEDIUM

Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticated attackers with low-level privileges to cause a Denial of Service …

Jul 14, 2026
CVE-2026-15753
5.4 MEDIUM

A vulnerability was determined in zhinianboke xianyu-auto-reply on Server. Affected by this vulnerability is an unknown functionality of the file /api/v1/payment/withdraw/review?action=approve. Executing a manipulation can …

Jul 14, 2026
CVE-2026-15751
5.3 MEDIUM

A security vulnerability has been detected in mastergo-design mastergo-magic-mcp up to 0.2.0. The affected element is the function execute of the file mastergo/component-workflow.md of the …

Jul 14, 2026
CVE-2026-59732
5.0 MEDIUM

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone archive extract can write …

Jul 14, 2026
CVE-2026-48357
6.2 MEDIUM

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust …

Jul 14, 2026
CVE-2026-48354
6.2 MEDIUM

CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability …

Jul 14, 2026
CVE-2026-48353
5.5 MEDIUM

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability …

Jul 14, 2026
CVE-2026-48312
6.8 MEDIUM

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability …

Jul 14, 2026
CVE-2026-48302
6.2 MEDIUM

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to …

Jul 14, 2026
CVE-2026-48298
6.2 MEDIUM

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this …

Jul 14, 2026
CVE-2026-48296
6.2 MEDIUM

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this …

Jul 14, 2026
CVE-2026-47732
6.5 MEDIUM

Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), …

Jul 14, 2026
CVE-2026-47730
5.4 MEDIUM

Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or …

Jul 14, 2026
CVE-2026-46639
6.5 MEDIUM

Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::getAttribute() with the sandbox argument hardcoded to false, disabling property and …

Jul 14, 2026
CVE-2026-46637
5.4 MEDIUM

Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to …

Jul 14, 2026
CVE-2026-46635
4.3 MEDIUM

Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), which reads public and magic properties …

Jul 14, 2026
CVE-2026-46629
6.5 MEDIUM

Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter instances in arrays keyed by template-controlled filter arguments such as …

Jul 14, 2026
CVE-2026-46628
5.4 MEDIUM

Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit …

Jul 14, 2026
CVE-2026-46627
6.5 MEDIUM

Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, …

Jul 14, 2026
CVE-2026-15750
6.3 MEDIUM

A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. Impacted is the function z.string of the file src/tools/get-component-link.ts of the component mcp__getComponentLink. Executing …

Jul 14, 2026
CVE-2026-59889
6.5 MEDIUM

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON …

Jul 14, 2026
CVE-2026-49854
5.3 MEDIUM

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask …

Jul 14, 2026
CVE-2026-49459
6.1 MEDIUM

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on …

Jul 14, 2026
CVE-2026-49458
6.1 MEDIUM

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes …

Jul 14, 2026
CVE-2026-48816
6.5 MEDIUM

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @sigstore/verify derives a transparency-log timestamp from tlogEntries[].integratedTime for bundle v0.2 inclusionProof-only entries even …

Jul 14, 2026
CVE-2026-48758
5.4 MEDIUM

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.2.1, the preAuthEncoding function in @sigstore/core uses Node.js ascii encoding when converting the PAE …

Jul 14, 2026
CVE-2026-48338
6.8 MEDIUM

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. …

Jul 14, 2026
CVE-2026-48308
5.9 MEDIUM

Premiere Pro is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to …

Jul 14, 2026
CVE-2026-48125
5.3 MEDIUM

UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From 2.0.1 until 2.0.10, a regular expression denial-of-service vulnerability …

Jul 14, 2026
CVE-2026-47979
5.5 MEDIUM

Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose …

Jul 14, 2026
CVE-2026-47475
6.2 MEDIUM

NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a reachable assertion in the sampler thread. A successful exploit …

Jul 14, 2026
CVE-2026-47470
6.2 MEDIUM

NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker could cause CWE-20 by local attack. A …

Jul 14, 2026
CVE-2026-24271
6.2 MEDIUM

NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API, where an attacker could cause allocation of GPU resources without limits or throttling. A successful …

Jul 14, 2026
CVE-2026-24259
6.4 MEDIUM

NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might …

Jul 14, 2026
CVE-2026-24234
6.8 MEDIUM

NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-accessible attacker could cause server-side request forgery. A successful exploit …

Jul 14, 2026
CVE-2026-24227
5.3 MEDIUM

NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Jul 14, 2026
CVE-2026-24226
6.3 MEDIUM

NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead …

Jul 14, 2026
CVE-2026-24220
6.4 MEDIUM

NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization. A …

Jul 14, 2026
CVE-2026-15778
6.5 MEDIUM

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to bypass …

Jul 14, 2026
CVE-2026-15775
6.5 MEDIUM

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium …

Jul 14, 2026
CVE-2026-15771
5.3 MEDIUM

Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process …

Jul 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.