CVE Database

48111+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-92753
7.1 HIGH

PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event …

Sep 16, 2026
CVE-2026-92752
8.3 HIGH

metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level permissions. Attackers can enumerate sequential document identifiers to read, replace, …

Sep 16, 2026
CVE-2026-92751
8.1 HIGH

CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated operators. Attackers can craft …

Sep 16, 2026
CVE-2026-92749
8.1 HIGH

SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key offline. Unauthenticated remote attackers who …

Sep 16, 2026
CVE-2026-92748
8.8 HIGH

BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on …

Sep 16, 2026
CVE-2026-76425
7.6 HIGH

A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database. This vulnerability …

Sep 16, 2026
CVE-2026-76424
7.2 HIGH

A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected device. …

Sep 16, 2026
CVE-2026-76413
8.2 HIGH

A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to …

Sep 16, 2026
CVE-2026-76412
8.5 HIGH

A vulnerability in the remote diagnostics debugger of Cisco Secure FMC Software could allow an authenticated, remote attacker to enable the remote diagnostics debugger service. …

Sep 16, 2026
CVE-2026-76409
8.8 HIGH

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. …

Sep 16, 2026
CVE-2026-63506
8.8 HIGH

Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the …

Sep 16, 2026
CVE-2026-20360
8.8 HIGH

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. …

Sep 16, 2026
CVE-2026-20352
8.6 HIGH

A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) …

Sep 16, 2026
CVE-2026-20344
8.8 HIGH

A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to perform a SQL injection attack against …

Sep 16, 2026
CVE-2026-20343
7.5 HIGH

A vulnerability in a critical API for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to download sensitive files and use unbounded disk …

Sep 16, 2026
CVE-2026-20342
7.7 HIGH

A vulnerability in a specific file download API of Cisco Secure FMC Software could allow an authenticated, remote attacker to download arbitrary files from an …

Sep 16, 2026
CVE-2026-20340
8.8 HIGH

A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands at the root privilege level. This vulnerability is due …

Sep 16, 2026
CVE-2026-20336
8.8 HIGH

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software …

Sep 16, 2026
CVE-2026-20335
8.1 HIGH

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software …

Sep 16, 2026
CVE-2026-20334
8.4 HIGH

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software …

Sep 16, 2026
CVE-2026-20333
8.8 HIGH

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software …

Sep 16, 2026
CVE-2026-20323
8.3 HIGH

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to …

Sep 16, 2026
CVE-2026-20300
7.1 HIGH

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected device. To exploit this vulnerability, the …

Sep 16, 2026
CVE-2026-20295
8.6 HIGH

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to …

Sep 16, 2026
CVE-2026-20250
8.6 HIGH

A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software …

Sep 16, 2026
CVE-2026-20249
8.6 HIGH

A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure …

Sep 16, 2026
CVE-2026-20247
7.5 HIGH

A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected device. This vulnerability is due to …

Sep 16, 2026
CVE-2026-20222
7.4 HIGH

A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow …

Sep 16, 2026
CVE-2026-20154
8.6 HIGH

A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat …

Sep 16, 2026
CVE-2026-20135
8.6 HIGH

A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected …

Sep 16, 2026
CVE-2025-56565
7.6 HIGH

DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in cleartext within non-volatile memory. The exposed material includes SSH …

Sep 16, 2026
CVE-2026-87976
8.1 HIGH

Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR …

Sep 16, 2026
CVE-2026-87105
8.8 HIGH

Tanium addressed a SQL injection vulnerability in Threat Response.

Sep 16, 2026
CVE-2026-87024
7.2 HIGH

Tanium addressed a SQL injection vulnerability in Asset.

Sep 16, 2026
CVE-2026-86865
7.2 HIGH

Tanium addressed a SQL injection vulnerability in Asset.

Sep 16, 2026
CVE-2026-86831
8.7 HIGH

Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an authenticated remote user to bypass NetworkPolicy …

Sep 16, 2026
CVE-2026-86089
7.1 HIGH

Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and …

Sep 16, 2026
CVE-2026-76646
7.5 HIGH

A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentially resulting in a denial of service condition. Older unsupported versions …

Sep 16, 2026
CVE-2026-70469
7.5 HIGH

Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip …

Sep 16, 2026
CVE-2026-20361
8.8 HIGH

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. …

Sep 16, 2026
CVE-2026-92729
8.2 HIGH

SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions …

Sep 16, 2026
CVE-2026-86043
7.5 HIGH

Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWithBody filter can authorize an oversized request after Skipper …

Sep 16, 2026
CVE-2026-86003
7.5 HIGH

CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC listeners in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call dns.Msg.Unpack …

Sep 16, 2026
CVE-2026-82399
7.5 HIGH

CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC request paths in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call …

Sep 16, 2026
CVE-2026-81876
7.5 HIGH

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can enter …

Sep 16, 2026
CVE-2026-81875
7.5 HIGH

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can consume …

Sep 16, 2026
CVE-2026-79298
8.4 HIGH

An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and fixed in v.11.3.0.34 allows a local attcker to execute arbitrary code via the …

Sep 16, 2026
CVE-2026-63325
7.8 HIGH

Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/respect-core and @redocly/cli, the respect command dynamically evaluates $faker runtime …

Sep 16, 2026
CVE-2026-63126
7.5 HIGH

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire protobuf readers do not consistently validate attacker-controlled …

Sep 16, 2026
CVE-2026-46352
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, Suricata's …

Sep 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.