CVE Database

48111+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-87902
8.1 HIGH KEV

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both …

Sep 22, 2026
CVE-2026-85740
7.1 HIGH

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parser/markdown/parser.py evaluates the literal resolved address with ipaddress.is_global without consistently classifying an IPv4 …

Sep 22, 2026
CVE-2026-83603
8.4 HIGH

Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-status-socket in src/collectors/utils/ndsudo.c accepts a caller-controlled --socket_path from the low-privileged …

Sep 22, 2026
CVE-2026-83599
7.5 HIGH

Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates permessage-deflate before authentication, and src/web/websocket/websocket-compression.c allows websocket_client_decompress_message() to grow decompressed …

Sep 22, 2026
CVE-2026-83598
7.8 HIGH

Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and …

Sep 22, 2026
CVE-2026-13087
8.8 HIGH

A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c. When a crafted RPC-over-RDMA client sends a large …

Sep 22, 2026
CVE-2026-95655
8.1 HIGH

Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access arbitrary messages. Attackers can submit …

Sep 22, 2026
CVE-2026-95654
7.4 HIGH

Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization decision without re-checking token validity during acceptance. Attackers with a …

Sep 22, 2026
CVE-2026-95653
7.5 HIGH

Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predictable. Unauthenticated attackers can …

Sep 22, 2026
CVE-2026-94640
7.5 HIGH

A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number …

Sep 22, 2026
CVE-2026-80150
7.5 HIGH

Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability …

Sep 22, 2026
CVE-2026-80149
8.6 HIGH

Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability …

Sep 22, 2026
CVE-2026-80148
8.6 HIGH

Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability …

Sep 22, 2026
CVE-2026-77633
7.1 HIGH

Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs/upload.go checks a stale in-memory user storage value through validateUserCapacity and …

Sep 22, 2026
CVE-2026-75608
7.7 HIGH

Frigate is an open source network video recorder. Prior to 0.18.0, the prefix-matched location /api/go2rtc/api in docker/main/rootfs/usr/local/nginx/conf/nginx.conf requires authentication but does not require an administrator …

Sep 22, 2026
CVE-2026-75607
8.1 HIGH

Frigate is an open source network video recorder. Prior to 0.17.2, the WebSocket handler in frigate/comms/ws.py forwards attacker-selected message topics to the dispatcher without checking …

Sep 22, 2026
CVE-2026-70410
8.8 HIGH

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite Avatica. Plugin instantiation (via AvaticaUtils#instantiatePlugin and other methods) initializes arbitrary …

Sep 22, 2026
CVE-2026-56681
7.3 HIGH

9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper trust …

Sep 22, 2026
CVE-2026-95500
7.3 HIGH

A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.php of the component Save Handler. …

Sep 22, 2026
CVE-2026-89407
7.5 HIGH

NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers …

Sep 22, 2026
CVE-2026-79314
8.8 HIGH

A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of other users, including remark, port, protocol, …

Sep 22, 2026
CVE-2026-65179
8.8 HIGH

NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controlled .pkl file via pickle.load() without validation. A successful exploit of …

Sep 22, 2026
CVE-2026-65178
7.8 HIGH

NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a maliciously crafted model_config.yaml can inject unsafe parameters. A successful exploit of this vulnerability may …

Sep 22, 2026
CVE-2026-65130
8.0 HIGH

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to …

Sep 22, 2026
CVE-2026-65128
8.8 HIGH

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code …

Sep 22, 2026
CVE-2026-65121
8.2 HIGH

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A successful exploit of this vulnerability might lead …

Sep 22, 2026
CVE-2026-65118
7.5 HIGH

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to …

Sep 22, 2026
CVE-2026-65114
8.3 HIGH

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability …

Sep 22, 2026
CVE-2026-65111
7.8 HIGH

NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection. A successful exploit of …

Sep 22, 2026
CVE-2026-24267
7.8 HIGH

NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious data created by an attacker could cause remote …

Sep 22, 2026
CVE-2026-24239
7.8 HIGH

NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an attacker could cause remote code execution. A successful exploit of …

Sep 22, 2026
CVE-2026-95499
7.3 HIGH

A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.php. Executing a manipulation of …

Sep 22, 2026
CVE-2026-95619
7.7 HIGH

A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This …

Sep 22, 2026
CVE-2026-95271
7.3 HIGH

A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the function check_authentication of the file changedetectionio/flask_app.py of the component …

Sep 22, 2026
CVE-2026-75791
8.6 HIGH

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.

Sep 22, 2026
CVE-2026-94117
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blind SQL Injection. This …

Sep 22, 2026
CVE-2026-25265
8.8 HIGH

Privilege escalation due to weak configuration while temporary file handling.

Sep 22, 2026
CVE-2026-25264
8.8 HIGH

Privilege escalation due to weak configuration during package extraction process.

Sep 22, 2026
CVE-2026-25255
8.8 HIGH

Exposed dangerous function lead to privilege escalation via gRPC server.

Sep 22, 2026
CVE-2026-9231
7.5 HIGH

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up …

Sep 22, 2026
CVE-2026-95508
7.4 HIGH

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, …

Sep 22, 2026
CVE-2026-93928
7.3 HIGH

Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Authentication Bypass. This issue affects Taxi Booking …

Sep 22, 2026
CVE-2026-93836
7.2 HIGH

The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' parameter in all versions up to, and …

Sep 22, 2026
CVE-2026-93778
7.2 HIGH

The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) in all versions up …

Sep 22, 2026
CVE-2026-92969
8.1 HIGH

The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.4 …

Sep 22, 2026
CVE-2026-92235
8.1 HIGH

The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.2. This is due …

Sep 22, 2026
CVE-2026-87082
7.5 HIGH

Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input …

Sep 22, 2026
CVE-2026-87081
7.5 HIGH

Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label before the length check in to_ascii. to_ascii punycode …

Sep 22, 2026
CVE-2026-87079
7.5 HIGH

Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode. The XS backend inserts each …

Sep 22, 2026
CVE-2026-74766
8.4 HIGH

Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode. The …

Sep 22, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.