CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-50022
5.8 MEDIUM

Metacat is data repository software that helps researchers preserve, share, and discover data. Prior to 3.4.2, MetacatSolrIndex.query forwards the client-controlled qt parameter through Apache SolrJ …

Sep 17, 2026
CVE-2021-3030
6.1 MEDIUM

Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GET parameter in colorpicker_more.aspx. A remote, unauthenticated …

Sep 17, 2026
CVE-2026-92993
6.3 MEDIUM

A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of the file server/internal/machine/api/machine_script.go of the component Machine …

Sep 17, 2026
CVE-2026-92758
5.5 MEDIUM

If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such …

Sep 17, 2026
CVE-2026-92757
5.5 MEDIUM

Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.

Sep 17, 2026
CVE-2026-92756
5.5 MEDIUM

Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings …

Sep 17, 2026
CVE-2026-54495
4.3 MEDIUM

The OpenFeature Operator allows users to expose feature flags to applications. In version 0.9.2 and earlier, a tenant who can create a controller-owned workload can …

Sep 17, 2026
CVE-2026-92992
6.3 MEDIUM

A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/ai/api/ai.go of the …

Sep 17, 2026
CVE-2026-52852
6.5 MEDIUM

Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups and request reports can create a …

Sep 17, 2026
CVE-2026-92927
5.3 MEDIUM

A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /db/drug_recommendor.sql. Performing a manipulation results in …

Sep 17, 2026
CVE-2026-89038
6.2 MEDIUM

Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging …

Sep 17, 2026
CVE-2026-54677
6.5 MEDIUM

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, authenticated users who are not members of a private space can …

Sep 17, 2026
CVE-2026-54676
6.5 MEDIUM

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, users with personal API tokens can retrieve replies from questions in …

Sep 17, 2026
CVE-2026-54551
4.3 MEDIUM

WireGuard Portal, or wg-portal, is a web-based configuration portal for WireGuard server management. From 2.2.0 until 2.3.0, the authenticated GET /api/v0/ws statistics WebSocket in internal/app/api/v0/handlers/endpoint_websocket.go …

Sep 17, 2026
CVE-2026-54546
5.0 MEDIUM

CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to 13.22.1, the authenticated PUT /api/basemap endpoint passes an attacker-controlled …

Sep 17, 2026
CVE-2026-44235
6.5 MEDIUM

rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized HEADER or METHOD frame during …

Sep 17, 2026
CVE-2026-8674
5.3 MEDIUM

Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or …

Sep 17, 2026
CVE-2026-85720
5.9 MEDIUM

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request …

Sep 17, 2026
CVE-2026-93015
6.3 MEDIUM

BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP stream endpoint discovery. A bonded peer can send an …

Sep 17, 2026
CVE-2026-93013
4.3 MEDIUM

RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary files by supplying absolute …

Sep 17, 2026
CVE-2026-92881
4.3 MEDIUM

A security vulnerability has been detected in vgmstream. The affected element is the function init_vgmstream_awb_memory of the file src/meta/awb.c of the component AWB parser. Such …

Sep 17, 2026
CVE-2026-86862
6.5 MEDIUM

pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql. libpq …

Sep 17, 2026
CVE-2026-86861
5.9 MEDIUM

pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the …

Sep 17, 2026
CVE-2026-86000
5.3 MEDIUM

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER …

Sep 17, 2026
CVE-2026-85999
5.3 MEDIUM

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector …

Sep 17, 2026
CVE-2026-85718
5.9 MEDIUM

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, a client with maxConnections …

Sep 17, 2026
CVE-2026-85717
6.8 MEDIUM

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to …

Sep 17, 2026
CVE-2026-81868
6.5 MEDIUM

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() …

Sep 17, 2026
CVE-2026-76781
5.5 MEDIUM

A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during …

Sep 17, 2026
CVE-2026-75523
5.9 MEDIUM

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, the Steeltoe.Management.Endpoint /actuator/httpexchanges endpoint …

Sep 17, 2026
CVE-2026-92880
6.3 MEDIUM

A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder.c of the component EA SCHl parser. …

Sep 17, 2026
CVE-2026-85078
6.5 MEDIUM

Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does not fully consume the trailer-part after the terminating zero …

Sep 17, 2026
CVE-2026-81447
6.8 MEDIUM

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this …

Sep 17, 2026
CVE-2026-63461
5.3 MEDIUM

Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop API products, collections, and facets queries combine mandatory visibility guards with caller-supplied …

Sep 17, 2026
CVE-2026-92973
6.1 MEDIUM

ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that fails to validate or escape URL targets. Attackers controlling …

Sep 17, 2026
CVE-2026-92963
5.3 MEDIUM

vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable. Attackers can access this internal state object through globalThis to retrieve …

Sep 17, 2026
CVE-2026-92952
6.8 MEDIUM

vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. The extraction filters in lib/setup-sandbox.js and the cross-realm symbol checks …

Sep 17, 2026
CVE-2026-92949
4.0 MEDIUM

vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() …

Sep 17, 2026
CVE-2026-92945
4.2 MEDIUM

vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted …

Sep 17, 2026
CVE-2026-92936
5.8 MEDIUM

vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting. Attacker-supplied code can force the host-realm source transformer …

Sep 17, 2026
CVE-2026-92933
5.8 MEDIUM

vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host `util` module to the sandbox as an unfiltered …

Sep 17, 2026
CVE-2026-92879
4.3 MEDIUM

A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the file src/meta/mus_acm.c. The manipulation results in …

Sep 17, 2026
CVE-2026-81829
5.3 MEDIUM

A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When …

Sep 17, 2026
CVE-2026-81453
6.5 MEDIUM

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged …

Sep 17, 2026
CVE-2026-81443
6.4 MEDIUM

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit …

Sep 17, 2026
CVE-2026-80355
5.4 MEDIUM

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this …

Sep 17, 2026
CVE-2026-78528
5.3 MEDIUM

Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions.

Sep 17, 2026
CVE-2026-78294
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.

Sep 17, 2026
CVE-2026-74017
5.3 MEDIUM

Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions.

Sep 17, 2026
CVE-2026-74005
5.4 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions.

Sep 17, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.