CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-61747
4.3 MEDIUM

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the /api/importer/row/ and /api/importer/mapping/ endpoints do not scope DataImportRow and DataImportColumnMap querysets to the …

Sep 21, 2026
CVE-2026-61746
5.3 MEDIUM

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, PluginSettingList, PluginAllSettingList, and PluginSettingDetail set GlobalSettingsPermissions without the IsAuthenticated permission used by the project …

Sep 21, 2026
CVE-2026-61744
6.5 MEDIUM

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /api/barcode/ accepts an attacker-synthesized internal JSON barcode containing a lowercase model label and …

Sep 21, 2026
CVE-2026-92382
4.1 MEDIUM

An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves the stream's single transfer buffer …

Sep 21, 2026
CVE-2026-69190
6.3 MEDIUM

Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for saved searches and dashboards …

Sep 21, 2026
CVE-2026-61745
4.3 MEDIUM

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the POST /api/machine/{pk}/restart/ endpoint in src/backend/InvenTree/machine/api.py uses IsAuthenticatedOrReadScope without requiring the ADMIN role used …

Sep 21, 2026
CVE-2026-61612
5.7 MEDIUM

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to version 0.4.108, the SSRF guard `validateServerUrl` (added for CVE-2026-33060, extended for …

Sep 21, 2026
CVE-2026-48974
5.4 MEDIUM

HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner …

Sep 21, 2026
CVE-2026-77561
5.3 MEDIUM

Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote attacker can send POST /api/user/login requests with 257 distinct nonexistent usernames to …

Sep 21, 2026
CVE-2026-63373
4.2 MEDIUM

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, the OAuth callback handler in src/main/java/com/mxgraph/online/AbsAuth.java skips comparison of stateToken and cookieToken whenever …

Sep 21, 2026
CVE-2026-63334
6.8 MEDIUM

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, deployments with ENABLE_DRAWIO_PROXY=1 are vulnerable to server-side request forgery because src/main/java/com/mxgraph/online/Utils.java performs the …

Sep 21, 2026
CVE-2026-62987
5.8 MEDIUM

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48865 fix in proxy/http_headers.go uses protectHeaders for …

Sep 21, 2026
CVE-2026-62866
6.2 MEDIUM

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.2, selector/lexer/tokenize.go parseCurRune advances the input index across …

Sep 21, 2026
CVE-2026-62370
6.5 MEDIUM

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.0.0 until 1.21.2, 1.22.2, and 1.23.1, Reader.Read …

Sep 21, 2026
CVE-2026-59168
6.2 MEDIUM

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.1, parsing/json/json_reader.go decodeValue, decodeObject, and decodeArray, and parsing/xml/reader.go …

Sep 21, 2026
CVE-2026-58504
6.1 MEDIUM

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.5, opening or importing a crafted .drawio file can execute attacker-controlled JavaScript in the …

Sep 21, 2026
CVE-2026-17051
6.0 MEDIUM

The Intel SEDI IPM (inter-processor mailbox) driver in drivers/ipm/ipm_sedi.c handles an inbound message interrupt in ipm_event_dispose(). It read the peer-written doorbell register, extracted the payload …

Sep 21, 2026
CVE-2026-17050
5.7 MEDIUM

The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicated usb_device_heap in usbh_device_set_configuration() (subsys/usb/host/usbh_device.c). On three failure paths — a failed …

Sep 21, 2026
CVE-2026-88978
4.3 MEDIUM

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.106.1, the WorkerStatus gRPC polling path in pkg/repository/durable_events.go …

Sep 21, 2026
CVE-2026-77165
6.5 MEDIUM

File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.

Sep 21, 2026
CVE-2026-63342
6.3 MEDIUM

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, api-contracts/openapi/paths/v1/workflow-runs/workflow_run.yaml defines the GET /api/v1/stable/durable-tasks/{durable-task} endpoint implemented …

Sep 21, 2026
CVE-2026-61681
4.1 MEDIUM

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, the SNS UnsubscribeConfirmation handler in internal/integrations/ingestors/sns/sns.go calls …

Sep 21, 2026
CVE-2026-36472
5.2 MEDIUM

CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allows a remote attacker to execute arbitrary JavaScript in …

Sep 21, 2026
CVE-2026-36471
5.8 MEDIUM

Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote attacker to inject arbitrary values into internal request variables …

Sep 21, 2026
CVE-2026-36470
5.8 MEDIUM

CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied into the response HTML unmodified/unescaped during …

Sep 21, 2026
CVE-2026-36468
6.1 MEDIUM

Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitrarily named URL parameter key, with part of its name …

Sep 21, 2026
CVE-2026-93339
5.4 MEDIUM

Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that allows authenticated users with Author-level privileges or higher to inject arbitrary HTML …

Sep 21, 2026
CVE-2026-82355
4.2 MEDIUM

When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the …

Sep 21, 2026
CVE-2026-75158
4.3 MEDIUM

Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized …

Sep 21, 2026
CVE-2026-61630
4.2 MEDIUM

nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can …

Sep 21, 2026
CVE-2026-55625
4.9 MEDIUM

GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/admin/internal/material_test and /go/api/internal/config_repos/*/material_test accept an arbitrary existing pipeline …

Sep 21, 2026
CVE-2026-52743
4.3 MEDIUM

GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs …

Sep 21, 2026
CVE-2026-94387
5.4 MEDIUM

Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping. …

Sep 21, 2026
CVE-2026-94382
4.2 MEDIUM

Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authenticated user to create or …

Sep 21, 2026
CVE-2025-71420
4.3 MEDIUM

UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support …

Sep 21, 2026
CVE-2025-71419
5.4 MEDIUM

UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject …

Sep 21, 2026
CVE-2026-94216
4.3 MEDIUM

A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This vulnerability affects the function authorize of the file …

Sep 21, 2026
CVE-2026-94214
4.3 MEDIUM

A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the file /login.html …

Sep 21, 2026
CVE-2026-91867
4.3 MEDIUM

When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly …

Sep 21, 2026
CVE-2026-94152
4.3 MEDIUM

A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown function of the file /user/ of the …

Sep 21, 2026
CVE-2026-94151
5.3 MEDIUM

A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /role-permission/permission of the component …

Sep 21, 2026
CVE-2026-92400
5.3 MEDIUM

The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured …

Sep 21, 2026
CVE-2026-85113
6.5 MEDIUM

The GiveWP WordPress plugin before 4.16.9 does not remove shortcode delimiters from donor-supplied values before rendering them on public pages, and the shortcode stripping it …

Sep 21, 2026
CVE-2026-85010
5.3 MEDIUM

The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated …

Sep 21, 2026
CVE-2026-94149
4.3 MEDIUM

A vulnerability was identified in Omega Solution HRM OS up to 20260717. The affected element is an unknown function of the file /role-permission/permission of the …

Sep 21, 2026
CVE-2026-94148
5.3 MEDIUM

A vulnerability was determined in ScadaBR up to 1.1. Impacted is the function EmportDwr.createExportJSON of the file /ScadaBR/export_project.htm of the component Export Project Endpoint. This …

Sep 21, 2026
CVE-2026-94215
5.5 MEDIUM

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs because the API uses …

Sep 21, 2026
CVE-2026-94213
4.9 MEDIUM

A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution. The issue occurs in the policy evaluation …

Sep 21, 2026
CVE-2026-94138
6.6 MEDIUM

A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. This impacts an unknown function of the file /send_order.cgi?parameter=del_expmac. The manipulation …

Sep 21, 2026
CVE-2026-94185
5.5 MEDIUM

nvm resolves a requested version or alias by treating it as a filename under $NVM_DIR/alias. Before 0.40.8, nvm_alias() concatenated the requested name onto that directory …

Sep 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.