CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-54778
6.2 MEDIUM

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF UnixDomainSocket POSIX peer …

Jul 8, 2026
CVE-2026-54776
4.4 MEDIUM

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service hosted …

Jul 8, 2026
CVE-2026-54775
6.5 MEDIUM

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service listening …

Jul 8, 2026
CVE-2026-54773
5.9 MEDIUM

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security signature verification …

Jul 8, 2026
CVE-2026-15131
4.3 MEDIUM

Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security …

Jul 8, 2026
CVE-2026-15130
4.3 MEDIUM

Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium …

Jul 8, 2026
CVE-2026-15128
6.1 MEDIUM

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML …

Jul 8, 2026
CVE-2026-15127
6.1 MEDIUM

Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML …

Jul 8, 2026
CVE-2026-15124
4.3 MEDIUM

Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. …

Jul 8, 2026
CVE-2026-15109
6.5 MEDIUM

Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted …

Jul 8, 2026
CVE-2026-15108
4.3 MEDIUM

Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to perform …

Jul 8, 2026
CVE-2026-15105
6.3 MEDIUM

A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the file src/core/s7_server.cpp of the component ReadVar Request …

Jul 8, 2026
CVE-2026-55877
6.1 MEDIUM

Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() Twig function is marked is_safe=['html'] and …

Jul 8, 2026
CVE-2026-54777
6.5 MEDIUM

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF NetNamedPipe transport accepts …

Jul 8, 2026
CVE-2026-48492
6.5 MEDIUM

Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can …

Jul 8, 2026
CVE-2026-39179
6.3 MEDIUM

A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the newPassword parameter in the password change functionality.

Jul 8, 2026
CVE-2026-39178
6.3 MEDIUM

A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the search parameter of the allContactSearch endpoint.

Jul 8, 2026
CVE-2026-8472
4.3 MEDIUM

GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain …

Jul 8, 2026
CVE-2026-7492
4.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain …

Jul 8, 2026
CVE-2026-59818
6.5 MEDIUM

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is configured with --listen-client-http-urls to …

Jul 8, 2026
CVE-2026-58494
6.5 MEDIUM

Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching FilePerms …

Jul 8, 2026
CVE-2026-58211
5.4 MEDIUM

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client could be registered …

Jul 8, 2026
CVE-2026-58208
6.8 MEDIUM

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener could route …

Jul 8, 2026
CVE-2026-58191
6.5 MEDIUM

Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 10.7.0, Appium's base-driver unconditionally …

Jul 8, 2026
CVE-2026-55542
4.3 MEDIUM

Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated …

Jul 8, 2026
CVE-2026-54590
5.9 MEDIUM

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Version …

Jul 8, 2026
CVE-2026-35211
6.5 MEDIUM

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260401.0, the OpenCTI GraphQL API exposes a script filter …

Jul 8, 2026
CVE-2026-15174
5.5 MEDIUM

Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Jul 8, 2026
CVE-2026-15173
4.7 MEDIUM

pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service

Jul 8, 2026
CVE-2026-15172
5.5 MEDIUM

FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Jul 8, 2026
CVE-2026-15171
5.5 MEDIUM

SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Jul 8, 2026
CVE-2026-15170
5.5 MEDIUM

Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Jul 8, 2026
CVE-2026-15169
5.5 MEDIUM

UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Jul 8, 2026
CVE-2026-15166
5.5 MEDIUM

IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Jul 8, 2026
CVE-2026-15165
5.5 MEDIUM

TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service

Jul 8, 2026
CVE-2026-15164
5.5 MEDIUM

Crash in ciscodump 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Jul 8, 2026
CVE-2026-15163
5.5 MEDIUM

Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allow denial of service

Jul 8, 2026
CVE-2026-14896
4.2 MEDIUM

HashiCorp Nomad and Nomad Enterprise are vulnerable to a cross-namespace authorization bypass in the dynamic host volumes feature that may allow an operator holding the …

Jul 8, 2026
CVE-2026-11827
4.9 MEDIUM

GitLab has remediated an issue in GitLab EE affecting all versions from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain …

Jul 8, 2026
CVE-2026-8650
4.5 MEDIUM

Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

Jul 8, 2026
CVE-2026-8649
6.4 MEDIUM

Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from …

Jul 8, 2026
CVE-2026-59947
4.7 MEDIUM

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug verbosity, it could print …

Jul 8, 2026
CVE-2026-59946
6.1 MEDIUM

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve …

Jul 8, 2026
CVE-2026-59820
6.5 MEDIUM

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not …

Jul 8, 2026
CVE-2026-59819
4.9 MEDIUM

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved request-supplied environment …

Jul 8, 2026
CVE-2026-59807
6.8 MEDIUM

Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and exfiltrate sensitive files by exploiting a missing assertSafeFileUploadPath check …

Jul 8, 2026
CVE-2026-59805
6.5 MEDIUM

Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authenticated sellers to manipulate purchase access for other sellers' products by …

Jul 8, 2026
CVE-2026-59804
6.8 MEDIUM

Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfiguration vulnerability that allows unauthenticated remote attackers to hijack active …

Jul 8, 2026
CVE-2026-58501
5.9 MEDIUM

Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is defined but not enforced when parsing WSDL or XSD documents, allowing transitive xsd:import, …

Jul 8, 2026
CVE-2026-58254
6.5 MEDIUM

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.8, message trace destination checks were …

Jul 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.