CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-89277
5.5 MEDIUM

CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability …

Sep 22, 2026
CVE-2026-84396
5.5 MEDIUM

InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash …

Sep 22, 2026
CVE-2026-83964
6.2 MEDIUM

Adobe Connect is affected by an Improper Certificate Validation vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to …

Sep 22, 2026
CVE-2026-77399
6.5 MEDIUM

icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 6.1.0 until 7.2.2, vInt.from_ical accepts an attacker-controlled VALARM REPEAT value …

Sep 22, 2026
CVE-2026-77272
5.4 MEDIUM

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth error query parameter is passed …

Sep 22, 2026
CVE-2026-77269
6.5 MEDIUM

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the remediation for CVE-2026-27825 protects download destinations …

Sep 22, 2026
CVE-2026-77268
5.5 MEDIUM

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth fallback token directory and JSON …

Sep 22, 2026
CVE-2026-77266
6.5 MEDIUM

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment accepts absolute paths and traversal sequences …

Sep 22, 2026
CVE-2026-77256
6.5 MEDIUM

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the plaintext OAuth fallback file containing refresh …

Sep 22, 2026
CVE-2026-77249
5.3 MEDIUM

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, JiraUserMixin._lookup_user_by_permissions uses the module-level requests.get function instead …

Sep 22, 2026
CVE-2026-77247
6.5 MEDIUM

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira and Confluence upload tools interpret caller-controlled …

Sep 22, 2026
CVE-2026-76194
4.3 MEDIUM

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability …

Sep 22, 2026
CVE-2026-76192
5.5 MEDIUM

InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash …

Sep 22, 2026
CVE-2026-75656
5.5 MEDIUM

Bridge is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive …

Sep 22, 2026
CVE-2026-75638
6.5 MEDIUM

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability …

Sep 22, 2026
CVE-2026-75634
4.3 MEDIUM

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability …

Sep 22, 2026
CVE-2026-75633
5.5 MEDIUM

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to …

Sep 22, 2026
CVE-2026-63386
5.3 MEDIUM

js-toml is a TOML parser for JavaScript. Prior to 1.1.3, load() does not bound nesting or dotted-key depth in the recursive parser at src/load/parser.ts or …

Sep 22, 2026
CVE-2026-48361
6.1 MEDIUM

Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form …

Sep 22, 2026
CVE-2026-37603
6.5 MEDIUM

Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0. The CAPTCHA escalation flag is stored …

Sep 22, 2026
CVE-2026-95660
6.3 MEDIUM

A security flaw has been discovered in Moonshot AI Kimi Code up to 0.31.0. The affected element is an unknown function of the file agent-core-v2/src/agent/mcp/config-loader.ts …

Sep 22, 2026
CVE-2026-95624
6.8 MEDIUM

The Tauri updater plugin's 'check' IPC command accepts an allowDowngrades boolean parameter directly from frontend JavaScript code. When set to true, it replaces the version …

Sep 22, 2026
CVE-2026-86056
5.5 MEDIUM

Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the NPPM_SAVESESSION handler in PowerEditor/src/NppBigSwitch.cpp converts lParam to a sessionInfo pointer and dereferences …

Sep 22, 2026
CVE-2026-85288
6.7 MEDIUM

Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ incompletely enforces shortcuts.xml HMAC validation because WM_MACRODLGRUNMACRO, the Run a Macro Multiple …

Sep 22, 2026
CVE-2026-77270
6.5 MEDIUM

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira and Confluence attachment upload tools …

Sep 22, 2026
CVE-2026-77265
5.9 MEDIUM

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, header-supplied Jira or Confluence URLs are resolved …

Sep 22, 2026
CVE-2026-77252
6.5 MEDIUM

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, caller-supplied projects_filter and spaces_filter arguments can replace …

Sep 22, 2026
CVE-2026-77250
6.1 MEDIUM

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, OAuthConfig writes a plaintext fallback file containing …

Sep 22, 2026
CVE-2026-86062
6.1 MEDIUM

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, lightrag_webui/src/components/retrieval/ChatMessage.tsx renders answer and thinking content with react-markdown, rehypeRaw, and skipHtml=false without an HTML sanitizer. …

Sep 22, 2026
CVE-2026-85725
5.9 MEDIUM

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwords.py compares plaintext AUTH_ACCOUNTS password values with Python's == operator. The comparison can …

Sep 22, 2026
CVE-2026-85709
5.3 MEDIUM

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, …

Sep 22, 2026
CVE-2026-84301
6.3 MEDIUM

FastGPT is an open-source LLM platform for building AI applications on a knowledge base. Prior to 4.15.2, the safe Axios request interceptor in packages/service/common/api/axios.ts validates …

Sep 22, 2026
CVE-2026-83602
6.5 MEDIUM

Netdata is an open source observability tool. From 2.0.0 until 2.11.0, Netdata registers /api/v3/settings in src/web/api/v3/web_api_v3.c with HTTP_ACL_NOCHECK and HTTP_ACCESS_ANONYMOUS_DATA, causing unauthenticated PUT requests handled …

Sep 22, 2026
CVE-2026-83601
6.5 MEDIUM

Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized DIMENSION SLOT value that str2ull_encoded passes to …

Sep 22, 2026
CVE-2026-83600
6.5 MEDIUM

Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized CHART SLOT value that str2ull_encoded passes to …

Sep 22, 2026
CVE-2026-76805
5.3 MEDIUM

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path in pkg/fuzz/parts.go can evaluate substituted runtime …

Sep 22, 2026
CVE-2026-76804
5.5 MEDIUM

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loading path does not enforce the -file …

Sep 22, 2026
CVE-2026-76803
5.3 MEDIUM

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript library does not enforce the local-file sandbox …

Sep 22, 2026
CVE-2026-76802
4.7 MEDIUM

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading branch does not apply the unsigned …

Sep 22, 2026
CVE-2026-56682
5.3 MEDIUM

9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper use …

Sep 22, 2026
CVE-2026-90462
5.4 MEDIUM

A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP …

Sep 22, 2026
CVE-2026-86805
6.3 MEDIUM

A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local …

Sep 22, 2026
CVE-2026-81886
5.5 MEDIUM

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Windows 64-bit crash-dump dmp64 parser was vulnerable because the Windows dmp64 …

Sep 22, 2026
CVE-2026-81885
5.5 MEDIUM

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's NE relocation fixup-chain parser was vulnerable because the NE relocation parser …

Sep 22, 2026
CVE-2026-81880
5.5 MEDIUM

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Apple Preferred Executable Format loader was vulnerable because the PEF loader …

Sep 22, 2026
CVE-2026-81879
5.5 MEDIUM

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's ELF PN_XNUM handling was vulnerable because the ELF parser allocated the …

Sep 22, 2026
CVE-2026-81878
5.5 MEDIUM

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's CPython bytecode .pyc marshal parser was vulnerable because the CPython marshal …

Sep 22, 2026
CVE-2026-79913
6.5 MEDIUM

Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, the ValidateExternalURL server-side request forgery guard in pkg/request/ssrf.go passes resolved addresses to checkIP …

Sep 22, 2026
CVE-2026-79312
6.8 MEDIUM

webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads session_id directly from the request cookie and loads that session from the store, …

Sep 22, 2026
CVE-2026-75517
6.5 MEDIUM

Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu integration mutation use cases including remove-integration, update-integration, auto-configure-integration, and set-integration-as-primary look …

Sep 22, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.