CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-47613
7.5 HIGH

NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted …

Aug 4, 2026
CVE-2026-47612
7.5 HIGH

NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted …

Aug 4, 2026
CVE-2026-24255
7.5 HIGH

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share …

Aug 4, 2026
CVE-2026-24253
8.2 HIGH

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial …

Aug 4, 2026
CVE-2026-18830
8.1 HIGH

Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via …

Aug 4, 2026
CVE-2026-18788
7.3 HIGH

A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager/dialog.php. The manipulation …

Aug 4, 2026
CVE-2026-56848
7.5 HIGH

A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, …

Aug 4, 2026
CVE-2026-18787
8.8 HIGH

A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the component RPC …

Aug 4, 2026
CVE-2026-15307
8.8 HIGH

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by …

Aug 4, 2026
CVE-2026-69100
8.8 HIGH

LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database …

Aug 4, 2026
CVE-2026-25292
7.6 HIGH

Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.

Aug 4, 2026
CVE-2026-25288
7.4 HIGH

Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.

Aug 4, 2026
CVE-2026-24084
7.5 HIGH

Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.

Aug 4, 2026
CVE-2026-24083
7.8 HIGH

Memory Corruption while processing IOCTL device driver requests with invalid arguments.

Aug 4, 2026
CVE-2026-24080
7.8 HIGH

Memory Corruption when handling malformed request parameters in the fingerprint TA.

Aug 4, 2026
CVE-2026-24079
8.1 HIGH

Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.

Aug 4, 2026
CVE-2026-21366
7.8 HIGH

Memory corruption while processing a packet with a size close to the maximum allowed value.

Aug 4, 2026
CVE-2026-67200
7.5 HIGH

Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files from the server filesystem by including literal ../ segments …

Aug 4, 2026
CVE-2026-67198
7.5 HIGH

Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to crash the server process by sending malformed or …

Aug 4, 2026
CVE-2026-67195
8.8 HIGH

Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the …

Aug 4, 2026
CVE-2026-18770
7.3 HIGH

A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /code of the component Python Validation …

Aug 4, 2026
CVE-2026-18650
8.8 HIGH

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MYS: from 2.2.3 before 2.3.1.

Aug 4, 2026
CVE-2026-11368
7.1 HIGH

The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data->att_chan = chan). When …

Aug 4, 2026
CVE-2026-17070
8.8 HIGH

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: from 2.2.3 before 2.3.1.

Aug 4, 2026
CVE-2026-70373
8.8 HIGH

Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concatenating several user-controlled request parameters directly into the SQL string. The …

Aug 4, 2026
CVE-2026-70372
8.8 HIGH

Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Criteria parameter is only normalized …

Aug 4, 2026
CVE-2026-70371
8.8 HIGH

Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Line and Column parameters are …

Aug 4, 2026
CVE-2026-70370
8.8 HIGH

Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directly into identifier positions of the query (SELECT …

Aug 4, 2026
CVE-2026-70369
8.8 HIGH

Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-controlled Filter request parameters directly into WHERE fragments covering aqbasket.closedate, aqorders.datereceived, aqbooksellers.name, …

Aug 4, 2026
CVE-2026-63252
7.5 HIGH

In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote …

Aug 4, 2026
CVE-2026-62927
7.5 HIGH

In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or …

Aug 4, 2026
CVE-2026-61387
7.5 HIGH

In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is …

Aug 4, 2026
CVE-2026-60007
7.4 HIGH

In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path …

Aug 4, 2026
CVE-2026-58080
8.2 HIGH

In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running …

Aug 4, 2026
CVE-2026-18806
7.1 HIGH

External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. This issue affects pardus-image-writer: …

Aug 4, 2026
CVE-2026-10710
7.8 HIGH

A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage …

Aug 4, 2026
CVE-2026-10709
7.8 HIGH

A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage …

Aug 4, 2026
CVE-2026-14838
7.4 HIGH

Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Session Hijacking. This …

Aug 4, 2026
CVE-2026-67243
7.2 HIGH

freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may …

Aug 4, 2026
CVE-2026-18755
7.3 HIGH

A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search directory to execute arbitrary code. By placing …

Aug 4, 2026
CVE-2026-16623
8.0 HIGH

The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a generated PHP pattern file, allowing a multisite …

Aug 4, 2026
CVE-2026-42169
7.3 HIGH

A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading …

Aug 4, 2026
CVE-2026-14818
7.2 HIGH

A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, …

Aug 4, 2026
CVE-2026-6837
7.2 HIGH

A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges …

Aug 4, 2026
CVE-2026-56846
7.5 HIGH

A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and …

Aug 4, 2026
CVE-2026-56845
7.5 HIGH

An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an …

Aug 4, 2026
CVE-2026-66322
7.1 HIGH

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Aug 4, 2026
CVE-2026-66321
7.4 HIGH

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Aug 4, 2026
CVE-2026-66318
8.1 HIGH

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Aug 4, 2026
CVE-2026-66315
7.5 HIGH

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Aug 4, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.