CVE Database

46976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-40592
5.9 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conversation/undo-reply/{thread_id}` checks only whether the current user …

Apr 21, 2026
CVE-2026-40590
4.3 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the Change Customer modal exposes a “Create a new customer” flow …

Apr 21, 2026
CVE-2026-40574
6.8 MEDIUM

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization bypass exists in OAuth2 Proxy as part of …

Apr 21, 2026
CVE-2026-40567
5.8 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can inject arbitrary HTML into outgoing emails generated …

Apr 21, 2026
CVE-2026-40566
4.1 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a Server-Side Request Forgery (SSRF) vulnerability in the IMAP/SMTP connection …

Apr 21, 2026
CVE-2026-35451
5.7 MEDIUM

Twenty is an open source CRM. Prior to 1.20.6, a Stored Cross-Site Scripting (XSS) vulnerability exists in the BlockNote editor component. Due to a lack …

Apr 21, 2026
CVE-2026-30452
6.5 MEDIUM

Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with low privileges to modify articles owned …

Apr 21, 2026
CVE-2026-26274
6.6 MEDIUM

October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identified in the Twig sandbox security policy …

Apr 21, 2026
CVE-2026-26067
4.9 MEDIUM

October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a server-side information disclosure vulnerability was identified in the handling …

Apr 21, 2026
CVE-2026-25542
6.5 MEDIUM

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. From 0.43.0 to 1.11.0, trusted resources verification policies match a resource source string (refSource.URI) against …

Apr 21, 2026
CVE-2026-24176
4.3 MEDIUM

NVIDIA KAI Scheduler contains a vulnerability where an attacker could cause improper authorization through cross-namespace pod references. A successful exploit of this vulnerability might lead …

Apr 21, 2026
CVE-2026-40565
6.1 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's linkify() function in app/Misc/Helper.php converts plain-text URLs in email bodies …

Apr 21, 2026
CVE-2025-41011
6.1 MEDIUM

HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack …

Apr 21, 2026
CVE-2026-31014
6.3 MEDIUM

Dovestones Softwares AD Self Update <4.0.0.5 is vulnerable to Cross Site Request Forgery (CSRF). The affected endpoint processes state-changing requests without requiring a CSRF token …

Apr 21, 2026
CVE-2026-31013
6.1 MEDIUM

Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cross-site scripting (XSS) vulnerability in the search parameter of the /ADPhonebook?Department=HR endpoint. User-supplied input is reflected in the …

Apr 21, 2026
CVE-2026-29644
5.3 MEDIUM

XiangShan (open-source high-performance RISC-V processor) commit edb1dfaf7d290ae99724594507dc46c2c2125384 (2024-11-28) has improper gating of its distributed CSR write-enable path, allowing illegal CSR write attempts to alter custom …

Apr 21, 2026
CVE-2026-1089
6.5 MEDIUM

User‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as DNS Rebinding and Information …

Apr 21, 2026
CVE-2026-0972
5.4 MEDIUM

HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, details, and description of this CVE were …

Apr 21, 2026
CVE-2026-0971
4.3 MEDIUM

An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login …

Apr 21, 2026
CVE-2025-31981
5.3 MEDIUM

HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access. An attacker with access …

Apr 21, 2026
CVE-2025-1241
5.8 MEDIUM

Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which allows admin users …

Apr 21, 2026
CVE-2026-6783
5.3 MEDIUM

Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Apr 21, 2026
CVE-2026-6779
5.3 MEDIUM

Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Apr 21, 2026
CVE-2026-6778
5.3 MEDIUM

Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Apr 21, 2026
CVE-2026-6777
5.3 MEDIUM

Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Apr 21, 2026
CVE-2026-6775
5.3 MEDIUM

Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Apr 21, 2026
CVE-2026-6774
5.4 MEDIUM

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Apr 21, 2026
CVE-2026-6770
6.5 MEDIUM

Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Apr 21, 2026
CVE-2026-6767
5.3 MEDIUM

Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird …

Apr 21, 2026
CVE-2026-6765
5.3 MEDIUM

Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Apr 21, 2026
CVE-2026-6764
6.5 MEDIUM

Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Apr 21, 2026
CVE-2026-6763
6.5 MEDIUM

Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Apr 21, 2026
CVE-2026-6762
6.3 MEDIUM

Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and …

Apr 21, 2026
CVE-2026-6757
6.3 MEDIUM

Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Apr 21, 2026
CVE-2026-6755
6.5 MEDIUM

Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Apr 21, 2026
CVE-2026-6712
4.4 MEDIUM

The Website LLMs.txt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.2.6 due to …

Apr 21, 2026
CVE-2026-6711
6.1 MEDIUM

The Website LLMs.txt plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 8.2.6. This …

Apr 21, 2026
CVE-2026-6703
4.3 MEDIUM

The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, …

Apr 21, 2026
CVE-2026-31370
6.3 MEDIUM

Honor E APP is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.

Apr 21, 2026
CVE-2026-6675
5.3 MEDIUM

The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to Unauthenticated Open Email Relay in all versions up to, …

Apr 21, 2026
CVE-2026-6674
6.5 MEDIUM

The Plugin: CMS für Motorrad Werkstätten plugin for WordPress is vulnerable to SQL Injection via the 'arttype' parameter in all versions up to, and including, …

Apr 21, 2026
CVE-2026-6058
4.5 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an …

Apr 21, 2026
CVE-2026-39886
5.3 MEDIUM

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. Versions 3.4.0 through 3.4.9 …

Apr 21, 2026
CVE-2026-39946
4.9 MEDIUM

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets …

Apr 21, 2026
CVE-2026-39378
6.5 MEDIUM

The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. In versions 6.5 through 7.17.0, when `HTMLExporter.embed_images=True`, nbconvert's markdown renderer …

Apr 21, 2026
CVE-2026-39377
6.5 MEDIUM

The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions 6.5 through 7.17.0 allow arbitrary file writes to locations …

Apr 21, 2026
CVE-2026-41331
5.3 MEDIUM

OpenClaw before 2026.3.31 contains a resource consumption vulnerability in Telegram audio preflight transcription that allows unauthorized group senders to trigger transcription processing. Attackers can exploit …

Apr 21, 2026
CVE-2026-41330
4.4 MEDIUM

OpenClaw before 2026.3.31 contains an environment variable override vulnerability in host exec policy that fails to properly enforce proxy, TLS, Docker, and Git TLS controls. …

Apr 21, 2026
CVE-2026-41301
5.3 MEDIUM

OpenClaw versions 2026.3.22 before 2026.3.31 contain a signature verification bypass vulnerability in the Nostr DM ingress path that allows pairing challenges to be issued before …

Apr 21, 2026
CVE-2026-41300
6.5 MEDIUM

OpenClaw before 2026.3.31 contains a trust-decline vulnerability that preserves attacker-discovered endpoints in remote onboarding flows. Attackers can route gateway credentials to malicious endpoints by having …

Apr 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.