CVE Database

48111+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-89777
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: clear vdev->msi_perm after freeing it on init failure vfio_msi_cap_len() lazily allocates the per-device MSI …

Sep 16, 2026
CVE-2026-89774
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: hold sk properly in sco_conn_ready sk deref in sco_conn_ready must be done either …

Sep 16, 2026
CVE-2026-81634
7.5 HIGH

In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer …

Sep 16, 2026
CVE-2026-73464
8.8 HIGH

On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted request could allow a malicious authenticated client with gRPC …

Sep 16, 2026
CVE-2026-73461
8.0 HIGH

On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the wrong privilege level, …

Sep 16, 2026
CVE-2026-73454
8.1 HIGH

On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target …

Sep 16, 2026
CVE-2026-73439
7.5 HIGH

On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNSI Pathz is configured and …

Sep 16, 2026
CVE-2026-2380
7.4 HIGH

On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged. These may …

Sep 16, 2026
CVE-2026-88263
7.5 HIGH

XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected …

Sep 16, 2026
CVE-2026-84408
8.8 HIGH

QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged in to a Windows PC …

Sep 16, 2026
CVE-2026-27564
7.2 HIGH

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of …

Sep 16, 2026
CVE-2026-27563
7.2 HIGH

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution …

Sep 16, 2026
CVE-2026-27562
7.2 HIGH

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution …

Sep 16, 2026
CVE-2026-27561
7.2 HIGH

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution …

Sep 16, 2026
CVE-2026-27560
7.2 HIGH

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution …

Sep 16, 2026
CVE-2026-27559
8.8 HIGH

A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution …

Sep 16, 2026
CVE-2026-27558
8.8 HIGH

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges on …

Sep 16, 2026
CVE-2026-27557
7.5 HIGH

An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read.

Sep 16, 2026
CVE-2026-27556
8.8 HIGH

A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP …

Sep 16, 2026
CVE-2026-27555
8.8 HIGH

A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP …

Sep 16, 2026
CVE-2026-27554
8.8 HIGH

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on …

Sep 16, 2026
CVE-2026-27552
8.1 HIGH

A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing …

Sep 16, 2026
CVE-2026-27551
8.8 HIGH

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on …

Sep 16, 2026
CVE-2026-27550
8.8 HIGH

A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on …

Sep 16, 2026
CVE-2026-27549
8.8 HIGH

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on …

Sep 16, 2026
CVE-2026-27548
8.8 HIGH

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root …

Sep 16, 2026
CVE-2026-27547
8.8 HIGH

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with …

Sep 16, 2026
CVE-2026-79708
8.5 HIGH

GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain …

Sep 16, 2026
CVE-2026-78252
8.2 HIGH

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain …

Sep 16, 2026
CVE-2026-1168
7.5 HIGH

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain …

Sep 16, 2026
CVE-2025-14871
7.5 HIGH

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain …

Sep 16, 2026
CVE-2026-86444
7.1 HIGH

The LearnPress WordPress plugin before 4.4.7 does not escape a user supplied value before using it in an HTML attribute on a public page, allowing …

Sep 16, 2026
CVE-2026-85569
7.2 HIGH

The Tutor LMS WordPress plugin before 4.0.8 does not correctly determine whether an incoming request is addressed to its own REST API, and does not …

Sep 16, 2026
CVE-2026-85530
8.1 HIGH

The GiveWP WordPress plugin before 4.16.8.1 does not consistently normalise a donor's e-mail address between the value it stores and the value it later uses …

Sep 16, 2026
CVE-2026-84829
8.8 HIGH

The Optimole WordPress plugin before 4.2.12 does not properly escape a user supplied value before using it to build an image tag attribute, allowing unauthenticated …

Sep 16, 2026
CVE-2026-78472
8.6 HIGH

The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated …

Sep 16, 2026
CVE-2026-76552
8.8 HIGH

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of files it retrieves from a user-supplied URL …

Sep 16, 2026
CVE-2026-76551
7.2 HIGH

The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict which PHP function may be applied to exported field values, allowing users granted …

Sep 16, 2026
CVE-2026-76550
7.2 HIGH

The WP Import Export Lite WordPress plugin before 3.9.34 does not validate a user-supplied output path when writing export files, allowing users granted its export …

Sep 16, 2026
CVE-2026-74926
7.1 HIGH

The MultiVendorX WordPress plugin before 5.0.16 does not verify that a user owns the store they are acting on in one of its REST API …

Sep 16, 2026
CVE-2026-89063
7.5 HIGH

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and …

Sep 16, 2026
CVE-2026-78088
8.8 HIGH

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in …

Sep 16, 2026
CVE-2026-18595
7.2 HIGH

The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via AJAX Cron Handler Request Parameter in all versions up to, …

Sep 16, 2026
CVE-2026-86108
8.0 HIGH

Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted …

Sep 16, 2026
CVE-2026-92299
7.4 HIGH

@jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() via contextBridge without requiring an active getDisplayMedia() picker, allowing any script in the meeting page to enumerate screens and windows. …

Sep 16, 2026
CVE-2026-92215
7.3 HIGH

A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is the function httpx.get of the file agent_sdks/python/a2ui_agent/src/a2ui/extensions/file_resolve/file_resolver.py of the …

Sep 16, 2026
CVE-2026-73459
7.4 HIGH

On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate …

Sep 16, 2026
CVE-2026-73446
7.4 HIGH

On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit …

Sep 16, 2026
CVE-2026-85893
8.8 HIGH

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

Sep 15, 2026
CVE-2026-69486
8.8 HIGH

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Sep 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.