CVE Database

48111+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-38999
7.5 HIGH

A Null Pointer Dereference in the mk_sched_event_close function (mk_server/mk_scheduler.c) of Monkey through commit 4fb0c16 allows attackers to cause a Denial of Service (DoS) via sending …

Sep 16, 2026
CVE-2026-92719
7.5 HIGH

Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing attackers to make the node issue …

Sep 16, 2026
CVE-2026-92718
7.3 HIGH

Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verified templates with unsigned malicious …

Sep 16, 2026
CVE-2026-92604
8.1 HIGH

Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows default User role users to write attacker-controlled JSON …

Sep 16, 2026
CVE-2026-92406
7.3 HIGH

A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown function of the file /admins/assessments/databank/btn_functions.php?action=add. Performing a manipulation …

Sep 16, 2026
CVE-2026-85387
7.1 HIGH

Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the state of the account the token …

Sep 16, 2026
CVE-2026-47094
8.8 HIGH

SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vulnerability that allows authenticated attackers to access and modify arbitrary employee records due to missing …

Sep 16, 2026
CVE-2026-92602
7.1 HIGH

TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController. Authenticated attackers can attach webhooks to other …

Sep 16, 2026
CVE-2026-92405
7.3 HIGH

A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element is an unknown function of the file /index.php. Such …

Sep 16, 2026
CVE-2026-92401
7.3 HIGH

A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects the function top.upstudy.crm.utils.LoginUserUtil.releaseUserIdFromCookie. The manipulation leads to improper authentication. The attack can …

Sep 16, 2026
CVE-2026-92399
7.3 HIGH

A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/utils/rmt_ws.c of the component WebSocket Handler. Executing a manipulation of …

Sep 16, 2026
CVE-2026-86359
8.5 HIGH

Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, …

Sep 16, 2026
CVE-2026-85756
7.5 HIGH

SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into the command used to run scp on …

Sep 16, 2026
CVE-2026-85731
8.8 HIGH

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store …

Sep 16, 2026
CVE-2026-71180
8.2 HIGH

Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this …

Sep 16, 2026
CVE-2026-71179
7.3 HIGH

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A …

Sep 16, 2026
CVE-2026-68904
7.0 HIGH

node-opcua is an OPC UA implementation for TypeScript and Node.js. From 2.0.0 until 2.170.0, node-opcua clients using the default keepSessionAlive setting can enter a repeated …

Sep 16, 2026
CVE-2026-59974
7.8 HIGH

Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.14.0, stanza.resources.common.unzip in stanza/resources/common.py passes …

Sep 16, 2026
CVE-2026-42784
7.4 HIGH

A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a …

Sep 16, 2026
CVE-2026-92626
7.5 HIGH

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may …

Sep 16, 2026
CVE-2026-92625
7.5 HIGH

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/restartService endpoint is reachable without authentication and invokes an …

Sep 16, 2026
CVE-2026-61595
7.7 HIGH

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. …

Sep 16, 2026
CVE-2026-61593
8.1 HIGH

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the SSE client→server POST endpoints are `@csrf_exempt` and the …

Sep 16, 2026
CVE-2026-17526
7.2 HIGH

Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. …

Sep 16, 2026
CVE-2025-43936
8.1 HIGH

Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to …

Sep 16, 2026
CVE-2026-92566
8.2 HIGH

DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to execute arbitrary HTTP requests by supplying a …

Sep 16, 2026
CVE-2026-92380
7.3 HIGH

A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file coreframe/app/attachment/index.php of the component Remote …

Sep 16, 2026
CVE-2026-92366
7.3 HIGH

A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search.php of the component Regular Search. This manipulation …

Sep 16, 2026
CVE-2026-92087
8.1 HIGH

@fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route guard. In versions 5.0.0 through 5.1.0, when strategies are …

Sep 16, 2026
CVE-2026-88064
8.8 HIGH

Backstage is an open framework for building developer portals. Prior to 1.14.6 and from 1.15.0 until 1.15.4, the @backstage/plugin-techdocs-node package insufficiently validates mkdocs.yml supplied by …

Sep 16, 2026
CVE-2026-84997
7.5 HIGH

react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, React\Http\Io\ChunkedDecoder could enter an infinite loop while processing a …

Sep 16, 2026
CVE-2026-84860
8.8 HIGH

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints by URL path pattern, but DWR itself dispatches method calls …

Sep 16, 2026
CVE-2026-84858
8.8 HIGH

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass The DWR "DataSourceEditDwr" class exposes the "validateScript" method that …

Sep 16, 2026
CVE-2026-82964
8.8 HIGH

Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file …

Sep 16, 2026
CVE-2026-80274
7.5 HIGH

If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 …

Sep 16, 2026
CVE-2026-79651
7.5 HIGH

A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management …

Sep 16, 2026
CVE-2026-76825
8.4 HIGH

RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython …

Sep 16, 2026
CVE-2026-76163
7.5 HIGH

If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may …

Sep 16, 2026
CVE-2026-74909
8.1 HIGH

Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails …

Sep 16, 2026
CVE-2026-63671
8.1 HIGH

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nuxtjs/mdc uses parseMarkdown with allowDangerousHtml …

Sep 16, 2026
CVE-2026-63128
7.5 HIGH

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP server in crates/rmcp/src/transport/streamable_http_server/tower.rs allows an …

Sep 16, 2026
CVE-2026-63127
8.2 HIGH

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 …

Sep 16, 2026
CVE-2026-19666
7.5 HIGH

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process …

Sep 16, 2026
CVE-2026-18212
7.5 HIGH

A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom …

Sep 16, 2026
CVE-2026-92469
8.1 HIGH

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate …

Sep 16, 2026
CVE-2026-92467
8.3 HIGH

zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by …

Sep 16, 2026
CVE-2026-92466
8.8 HIGH

zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated users with …

Sep 16, 2026
CVE-2026-92362
7.3 HIGH

A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the file crates/ag-ui-client/src/sse.rs of the component SSE Frame Parser. Performing a …

Sep 16, 2026
CVE-2026-92137
8.8 HIGH

Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the build …

Sep 16, 2026
CVE-2026-92136
8.0 HIGH

Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the Jenkins UI, resulting in a stored cross-site scripting …

Sep 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.