CVE Database

48111+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-84398
7.5 HIGH

CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected …

Sep 18, 2026
CVE-2026-84384
7.5 HIGH

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF or AVIF mime metadata and unci image data …

Sep 18, 2026
CVE-2026-81944
7.5 HIGH

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds …

Sep 18, 2026
CVE-2026-81942
8.8 HIGH

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain an OS command injection vulnerability in the web server. User-supplied …

Sep 18, 2026
CVE-2026-7006
7.3 HIGH

Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege escalation vulnerability that allows unprivileged …

Sep 18, 2026
CVE-2026-67549
7.6 HIGH

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, A …

Sep 18, 2026
CVE-2026-63638
8.3 HIGH

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, …

Sep 18, 2026
CVE-2026-63422
7.8 HIGH

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, …

Sep 18, 2026
CVE-2026-63419
7.8 HIGH

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, …

Sep 18, 2026
CVE-2026-54148
8.1 HIGH

http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest does not compare the uri parameter in …

Sep 18, 2026
CVE-2026-11381
8.8 HIGH

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of message distribution …

Sep 18, 2026
CVE-2026-11378
8.8 HIGH

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution …

Sep 18, 2026
CVE-2026-11375
8.8 HIGH

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when …

Sep 18, 2026
CVE-2026-10853
7.5 HIGH

IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation …

Sep 18, 2026
CVE-2026-10751
7.5 HIGH

IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass …

Sep 18, 2026
CVE-2026-10744
7.5 HIGH

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to …

Sep 18, 2026
CVE-2026-10575
8.8 HIGH

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing …

Sep 18, 2026
CVE-2026-10030
7.1 HIGH

IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.

Sep 18, 2026
CVE-2026-10027
8.1 HIGH

IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed …

Sep 18, 2026
CVE-2025-61682
8.6 HIGH

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and …

Sep 18, 2026
CVE-2025-14754
8.8 HIGH

IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation …

Sep 18, 2026
CVE-2025-14753
7.5 HIGH

IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL …

Sep 18, 2026
CVE-2026-93659
8.7 HIGH

Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in …

Sep 18, 2026
CVE-2026-93658
7.0 HIGH

uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned …

Sep 18, 2026
CVE-2026-93657
7.5 HIGH

hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful …

Sep 18, 2026
CVE-2026-93652
7.5 HIGH

Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause DoS

Sep 18, 2026
CVE-2026-93576
7.5 HIGH

A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in the SMTP command-name …

Sep 18, 2026
CVE-2026-93569
8.2 HIGH

A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request …

Sep 18, 2026
CVE-2026-93568
7.5 HIGH

A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended CONNECT requests. Netty's HTTP-object …

Sep 18, 2026
CVE-2026-93567
7.5 HIGH

A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the …

Sep 18, 2026
CVE-2026-93565
7.5 HIGH

A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes from method tokens in Real-Time Streaming Protocol (RTSP) requests. A …

Sep 18, 2026
CVE-2026-93564
7.5 HIGH

A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticated attacker to send specially crafted PROXY-protocol …

Sep 18, 2026
CVE-2026-93558
7.5 HIGH

A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to send requests faster than the …

Sep 18, 2026
CVE-2026-77929
8.8 HIGH

ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid …

Sep 18, 2026
CVE-2026-93604
7.2 HIGH

vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allowlists the crypto builtin for a NodeVM (require.builtin: ['crypto']). The …

Sep 18, 2026
CVE-2026-93599
7.5 HIGH

rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT …

Sep 18, 2026
CVE-2026-93597
7.7 HIGH

ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attackers can supply …

Sep 18, 2026
CVE-2026-93594
8.1 HIGH

ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file id. Query-execution paths that reach record data through …

Sep 18, 2026
CVE-2026-93593
8.1 HIGH

ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but TimeSeries types …

Sep 18, 2026
CVE-2026-93592
7.5 HIGH

vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the …

Sep 18, 2026
CVE-2026-93591
7.6 HIGH

SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without …

Sep 18, 2026
CVE-2026-93560
7.5 HIGH

A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header exceeding the …

Sep 18, 2026
CVE-2026-88623
7.5 HIGH

NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the user via POST is received, and …

Sep 18, 2026
CVE-2026-88622
8.8 HIGH

NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.

Sep 18, 2026
CVE-2023-5778
7.5 HIGH

Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900. …

Sep 18, 2026
CVE-2026-93491
7.5 HIGH

A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding …

Sep 18, 2026
CVE-2026-93488
7.5 HIGH

A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no …

Sep 18, 2026
CVE-2026-28198
8.8 HIGH

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command …

Sep 18, 2026
CVE-2026-28197
8.8 HIGH

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing …

Sep 18, 2026
CVE-2026-93575
7.5 HIGH

A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. The decoder …

Sep 18, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.