CVE Database

48111+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-93435
7.5 HIGH

redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through …

Sep 17, 2026
CVE-2026-87886
7.8 HIGH KEV

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis …

Sep 17, 2026
CVE-2026-85917
7.5 HIGH

Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Sep 17, 2026
CVE-2026-78501
7.4 HIGH

Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over …

Sep 17, 2026
CVE-2026-68791
8.6 HIGH

Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.

Sep 17, 2026
CVE-2026-93426
8.5 HIGH

SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with …

Sep 17, 2026
CVE-2026-54671
8.8 HIGH

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web/dao/MiddlewareDAO.php …

Sep 17, 2026
CVE-2026-54647
7.2 HIGH

CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the administrator-controlled download_expire POST parameter into a raw UPDATE statement for CubeCart_downloads without …

Sep 17, 2026
CVE-2026-54646
7.2 HIGH

CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values into ALTER TABLE, CHECK TABLE, and ANALYZE TABLE statements without validating …

Sep 17, 2026
CVE-2026-54634
7.3 HIGH

Hamlib is a ham radio control library for radios, rotators, and amplifiers. Prior to 4.7.2, the unauthenticated rigctld send_raw command on TCP port 4532 reaches …

Sep 17, 2026
CVE-2026-54612
8.8 HIGH

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until 1.0.8.5, saveGlobalElements() in …

Sep 17, 2026
CVE-2026-54520
8.1 HIGH

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js …

Sep 17, 2026
CVE-2026-54519
8.8 HIGH

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, backend/src/controllers/memory.controller.js authenticates requests but listMemories, deleteMemory, …

Sep 17, 2026
CVE-2026-54506
7.6 HIGH

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, app/controller/user/profile.php accepts the …

Sep 17, 2026
CVE-2026-50158
7.7 HIGH

yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool accepts a caller-controlled file parameter through cmd/caption/download.go …

Sep 17, 2026
CVE-2026-93393
8.1 HIGH

A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote …

Sep 17, 2026
CVE-2026-93382
8.8 HIGH

Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Sep 17, 2026
CVE-2026-93381
8.8 HIGH

Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code …

Sep 17, 2026
CVE-2026-93377
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via …

Sep 17, 2026
CVE-2026-93375
8.1 HIGH

Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the …

Sep 17, 2026
CVE-2026-86049
7.1 HIGH

Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the Referer header into …

Sep 17, 2026
CVE-2026-77615
8.7 HIGH

Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to …

Sep 17, 2026
CVE-2026-76154
7.3 HIGH

A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another …

Sep 17, 2026
CVE-2026-68537
7.5 HIGH

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child …

Sep 17, 2026
CVE-2026-68523
7.5 HIGH

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child …

Sep 17, 2026
CVE-2026-54916
8.8 HIGH

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The absence of tests/init.py and the lack of --import-mode=importlib …

Sep 17, 2026
CVE-2026-54597
8.3 HIGH

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated user with module_support write permission …

Sep 17, 2026
CVE-2026-54596
8.1 HIGH

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated Technician or higher with access …

Sep 17, 2026
CVE-2026-54510
7.1 HIGH

Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the csrf_exempt_for_api_tokens() before_request hook in src/app.py calls csrf.exempt(view_func), permanently adding …

Sep 17, 2026
CVE-2026-54354
8.2 HIGH

MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFilter() treats a filteritem as …

Sep 17, 2026
CVE-2026-54339
7.7 HIGH

Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/discover passes an attacker-supplied feed_url to discover_feed(feed_url), creates a subscription …

Sep 17, 2026
CVE-2026-52483
8.8 HIGH

The ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(WVK.0)b46 allow authenticated users execute arbitrary OS command via concatenated params …

Sep 17, 2026
CVE-2026-50277
7.5 HIGH

dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-cpp parses incoming W3C baggage headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES on the …

Sep 17, 2026
CVE-2026-50275
7.5 HIGH

The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddtrace_deserialize_baggage in ext/distributed_tracing_headers.c parses incoming W3C baggage HTTP headers …

Sep 17, 2026
CVE-2026-15815
8.8 HIGH

Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries …

Sep 17, 2026
CVE-2026-93337
7.8 HIGH

NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd …

Sep 17, 2026
CVE-2026-92943
8.1 HIGH

Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on …

Sep 17, 2026
CVE-2026-54716
7.5 HIGH

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources_to_targets containing …

Sep 17, 2026
CVE-2026-54692
7.8 HIGH

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allocates …

Sep 17, 2026
CVE-2026-50285
7.5 HIGH

Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs zstd decompression of attacker-controlled data without an output-memory limit when …

Sep 17, 2026
CVE-2026-50125
7.5 HIGH

MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, cmd/server/main.go exposes the default HTTP endpoint and pkg/mcp/server.go registers the unauthenticated get_resource tool, …

Sep 17, 2026
CVE-2026-45726
7.6 HIGH

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a standalone Talos cluster creates an …

Sep 17, 2026
CVE-2026-45720
7.0 HIGH

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.getSession in internal/pkg/auth/interceptor/saml.go checks SAMLAssertion.Used …

Sep 17, 2026
CVE-2026-92230
7.5 HIGH

Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLocal value outlives the OSGi bundle that created …

Sep 17, 2026
CVE-2026-90997
7.4 HIGH

A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and …

Sep 17, 2026
CVE-2026-54504
8.8 HIGH

MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13.0 until 1.13.1, the automatically started Web UI …

Sep 17, 2026
CVE-2026-54253
8.2 HIGH

TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in packages/server/routes/api.js passes the attacker-controlled port query parameter to …

Sep 17, 2026
CVE-2026-54239
8.8 HIGH

Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertext in its token envelope and excludes the 16-byte …

Sep 17, 2026
CVE-2026-52851
7.1 HIGH

Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an object usable in a permission pair …

Sep 17, 2026
CVE-2026-52727
7.2 HIGH

lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publication, images built from images/archlinux.yaml retain the same pacman …

Sep 17, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.