CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-88756
5.3 MEDIUM

Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the credentials array submitted to the public login endpoint (POST /user/authenticate).

Sep 21, 2026
CVE-2026-78806
5.5 MEDIUM

An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive information via the PerformCommissioningStep function in …

Sep 21, 2026
CVE-2026-61743
6.3 MEDIUM

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's …

Sep 21, 2026
CVE-2026-59830
5.4 MEDIUM

Discourse is an open-source discussion platform. Prior to 2026.7.0, the post action component failed to escape user-controlled display names before interpolating them into an HTML …

Sep 21, 2026
CVE-2026-59815
4.3 MEDIUM

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's ItemModel.checkIfAllowed() authorizes writes to …

Sep 21, 2026
CVE-2026-46650
4.4 MEDIUM

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, isAcceptedUrl() in packages/renderer/htmlUtils.ts uses an unanchored …

Sep 21, 2026
CVE-2026-17054
5.3 MEDIUM

The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-processor in esp_hosted_event_task(). For control frames it took the 16-bit TLV …

Sep 21, 2026
CVE-2026-15890
5.3 MEDIUM

The default AEAD nonce provider for the PSA Internal Trusted Storage transform module, secure_storage_its_transform_aead_get_nonce() in subsys/secure_storage/src/its/transform/aead_get.c, stores its nonce counter in unsynchronized function-local static variables …

Sep 21, 2026
CVE-2026-94588
4.4 MEDIUM

In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is caused by improper handling of user-supplied input passed to …

Sep 21, 2026
CVE-2026-93433
5.5 MEDIUM

A flaw was found in libstoragemgmt. An attacker with control over a local or virtual storage device could provide specially crafted SCSI (Small Computer System …

Sep 21, 2026
CVE-2026-88745
6.1 MEDIUM

EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell.

Sep 21, 2026
CVE-2026-88412
5.3 MEDIUM

An integer overflow in the _BulkInsert_ReadProperty component (/bulk_insert.c) of FalkorDB (Redis module) v4.20.1 allows attackers to cause a Denial of Service (DoS) via a crafted …

Sep 21, 2026
CVE-2026-88408
6.5 MEDIUM

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _GetGroup() function (/ops/op_aggregate.c). This vulnerability allows attackers to cause a …

Sep 21, 2026
CVE-2026-88403
6.5 MEDIUM

A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request.

Sep 21, 2026
CVE-2026-79919
6.3 MEDIUM

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, function-library code running under the LD_PRELOAD sandbox can invoke ctypes.CDLL from an importlib.abc.MetaPathFinder …

Sep 21, 2026
CVE-2026-79918
6.3 MEDIUM

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, the ToolExecutor LD_PRELOAD sandbox hooks execve, execvpe, and execveat to prevent subprocess creation …

Sep 21, 2026
CVE-2026-79917
6.5 MEDIUM

MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through 2.10.4-lts, POST /chat/api/{application_id}/chat/{chat_id}/share_chat verifies that a conversation exists but does not verify that it …

Sep 21, 2026
CVE-2026-79317
4.8 MEDIUM

A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored in a client-side signed cookie, and authentication only checks that a …

Sep 21, 2026
CVE-2026-77525
4.2 MEDIUM

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, management chat-record routes authorize the path application_id but load records using global chat_id …

Sep 21, 2026
CVE-2026-77522
4.3 MEDIUM

MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the knowledge web-document import and synchronization crawler passes an authenticated workspace user's …

Sep 21, 2026
CVE-2026-77520
5.4 MEDIUM

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal user in the same workspace can obtain another user's application_id from …

Sep 21, 2026
CVE-2026-77519
5.4 MEDIUM

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, the /chat/api/mcp authentication path looks up an ApplicationApiKey using only its secret and …

Sep 21, 2026
CVE-2026-77518
5.0 MEDIUM

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal workspace user who knows another user's active MCP tool_id in the …

Sep 21, 2026
CVE-2026-77517
5.4 MEDIUM

MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.10.2-lts, document and paragraph operate routes authorize only knowledge_id in the request path, …

Sep 21, 2026
CVE-2026-77516
5.4 MEDIUM

MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.9.2, a lowest-role workspace member denied access to a tool by WorkspaceUserResourcePermission can …

Sep 21, 2026
CVE-2026-73551
5.3 MEDIUM

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's URL normalization does not …

Sep 21, 2026
CVE-2026-73511
5.3 MEDIUM

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy normally matches the raw …

Sep 21, 2026
CVE-2026-59816
4.3 MEDIUM

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, the GET /api/transcribe/:id and POST /api/transcribe/:id …

Sep 21, 2026
CVE-2026-58272
5.3 MEDIUM

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prior to 2.4.1 contain an observable timing discrepancy in the login …

Sep 21, 2026
CVE-2026-58270
6.5 MEDIUM

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, the sync diff endpoint compiles a user-supplied string …

Sep 21, 2026
CVE-2026-55179
6.5 MEDIUM

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /items/:id/content route in …

Sep 21, 2026
CVE-2026-79320
6.1 MEDIUM

Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerability in the component runtime. When a downstream application enables the experimental slot fixes option and …

Sep 21, 2026
CVE-2026-79319
5.3 MEDIUM

Stencil core 4.43.5 is vulnerable to Incorrect Access Control.

Sep 21, 2026
CVE-2026-79318
6.5 MEDIUM

web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file()/write_file() (applications/admin/controllers/webservices.py).

Sep 21, 2026
CVE-2026-73549
5.3 MEDIUM

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's Utility::copyInternetAddressAndPort and QUIC client-address …

Sep 21, 2026
CVE-2026-62247
6.5 MEDIUM

Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets. Prior to 2.111.2, Realtime authorization does not correctly honor the per-extension presence.read row-level security policy …

Sep 21, 2026
CVE-2026-58271
6.8 MEDIUM

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/app/sync/register` accepts credentials and a TOTP code …

Sep 21, 2026
CVE-2026-54915
5.4 MEDIUM

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the unauthenticated /auth/redirect endpoint in plexpy/webauth.py removes forward slashes …

Sep 21, 2026
CVE-2026-50572
5.9 MEDIUM

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HTTP external-authorization client can …

Sep 21, 2026
CVE-2026-48521
5.9 MEDIUM

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ProdClusterManagerFactory::allocateConnPool dereferences transport_socket_options while …

Sep 21, 2026
CVE-2026-94494
5.0 MEDIUM

jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the GET /tenant/info endpoint. Attackers can …

Sep 21, 2026
CVE-2026-94414
5.4 MEDIUM

jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authenticated users to modify role button-permission definitions. Attackers can supply …

Sep 21, 2026
CVE-2026-94413
6.5 MEDIUM

jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve unsalted MD5 password digests for any user. Attackers …

Sep 21, 2026
CVE-2026-91166
5.7 MEDIUM

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.25.0 until 0.27.6, the browser SSH path in warpgate-web-ssh/src/manager.rs handles RCEvent::HostKeyUnknown …

Sep 21, 2026
CVE-2026-91164
4.3 MEDIUM

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.23.0 until 0.27.3, HTTP API token authentication resolves ConfigProvider::validate_api_token into RequestAuthorization::UserToken …

Sep 21, 2026
CVE-2026-82165
5.5 MEDIUM

Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access …

Sep 21, 2026
CVE-2026-82163
5.5 MEDIUM

Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access …

Sep 21, 2026
CVE-2026-63329
4.9 MEDIUM

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request in warpgate-protocol-http/src/proxy.rs forwards a client-supplied x-warpgate-username header before …

Sep 21, 2026
CVE-2026-61749
6.5 MEDIUM

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author report or label templates can cause WeasyPrint report …

Sep 21, 2026
CVE-2026-61748
4.3 MEDIUM

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, ReportPrint at POST /api/report/print/ and LabelPrint at POST /api/report/label/print/ require authentication but do not …

Sep 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.