CVE Database

4751+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-13235
3.3 LOW

Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to …

Jul 10, 2026
CVE-2026-13233
3.3 LOW

Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. This issue affects OpenAI Provider versions: from 0.0.0 to 1.1.1, from …

Jul 10, 2026
CVE-2026-13232
3.1 LOW

Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to …

Jul 10, 2026
CVE-2026-11909
3.3 LOW

Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6.

Jul 10, 2026
CVE-2026-59180
3.1 LOW

Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available. Prior to …

Jul 10, 2026
CVE-2026-61492
3.5 LOW

In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible

Jul 10, 2026
CVE-2026-59791
3.5 LOW

In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible

Jul 10, 2026
CVE-2026-57961
2.7 LOW

phpMyFAQ before 4.1.5 contains a potential authenticated path traversal vulnerability in the concatenatePaths() function within src/phpMyFAQ/Export/Pdf/Wrapper.php. A user with FAQ editing privileges can store HTML …

Jul 10, 2026
CVE-2026-56373
3.7 LOW

ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability …

Jul 10, 2026
CVE-2026-56366
3.3 LOW

ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing …

Jul 10, 2026
CVE-2026-15028
3.9 LOW

A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The …

Jul 10, 2026
CVE-2026-15326
3.8 LOW

A vulnerability was identified in halo-dev halo up to 2.24.2. This affects the function ThemeUtils.unzipThemeTo of the file ThemeUtils.java of the component Theme Installation. Such …

Jul 10, 2026
CVE-2026-15321
2.4 LOW

A vulnerability was found in MyEMS up to 6.4.0. The affected element is the function on_post of the file myems-api/core/svg.py of the component Admin Backend. …

Jul 10, 2026
CVE-2026-15311
3.5 LOW

A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function MatrixAdapter._markdown_to_html of the file gateway/platforms/matrix.py of the component …

Jul 10, 2026
CVE-2026-15276
3.3 LOW

A flaw has been found in pdeljanov Symphonia up to 0.6.0. This vulnerability affects unknown code of the component Metadata Handler. This manipulation causes denial …

Jul 9, 2026
CVE-2026-15274
3.3 LOW

A vulnerability was detected in lo48576 fbxcel up to 0.9.0. This affects an unknown part of the file src/pull_parser/v7400/parser.rs of the component Node Header Handler. …

Jul 9, 2026
CVE-2026-59715
3.1 LOW

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.16 before 0.10.0, the Socket.IO server is configured with always_connect=True. The ydoc:awareness:update and …

Jul 9, 2026
CVE-2026-59226
3.1 LOW

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_automation rehydrated automation owners without rechecking that they were still …

Jul 9, 2026
CVE-2026-59215
3.1 LOW

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread parent and reply handling did not bind parent_id to …

Jul 9, 2026
CVE-2026-59213
3.5 LOW

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 before 0.10.0, get_all_models handlers in routers/openai.py and routers/ollama.py passed a lambda to …

Jul 9, 2026
CVE-2026-15194
3.3 LOW

A security flaw has been discovered in Open5GS 2.7.7. This affects the function amf_context_final of the file src/amf/context.c of the component AMF. Performing a manipulation …

Jul 9, 2026
CVE-2026-15185
3.3 LOW

A vulnerability was determined in GPAC 26.03-DEV. This affects the function vobsub_read_idx of the file /src/media_tools/vobsub.c of the component MP4Box. Executing a manipulation of the …

Jul 9, 2026
CVE-2026-15184
3.3 LOW

A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_next_entity of the file src/dwg.c of the component DWG …

Jul 9, 2026
CVE-2026-12590
3.7 LOW

Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such …

Jul 9, 2026
CVE-2026-59269
3.8 LOW

A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in the clusters, only if all the following conditions were …

Jul 9, 2026
CVE-2026-54780
3.7 LOW

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, the CoreWCF WS-Security 1.0 …

Jul 8, 2026
CVE-2026-15115
3.3 LOW

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.115 allowed a local attacker to bypass same origin policy via …

Jul 8, 2026
CVE-2026-15168
2.5 LOW

BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure

Jul 8, 2026
CVE-2026-6352
2.7 LOW

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain …

Jul 8, 2026
CVE-2026-13151
2.7 LOW

GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain …

Jul 8, 2026
CVE-2025-12506
3.5 LOW

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain …

Jul 8, 2026
CVE-2026-8801
3.5 LOW

Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.

Jul 8, 2026
CVE-2026-8800
2.7 LOW

Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

Jul 8, 2026
CVE-2026-8651
3.7 LOW

Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

Jul 8, 2026
CVE-2026-14967
3.1 LOW

BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, so a …

Jul 8, 2026
CVE-2026-14966
3.1 LOW

BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect symlinks whose listing carries a …

Jul 8, 2026
CVE-2026-56374
3.3 LOW

ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger …

Jul 8, 2026
CVE-2026-56362
3.3 LOW

ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger …

Jul 8, 2026
CVE-2026-53480
2.7 LOW

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through …

Jul 8, 2026
CVE-2026-15041
3.7 LOW

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison …

Jul 8, 2026
CVE-2026-60000
3.7 LOW

sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for …

Jul 8, 2026
CVE-2026-28378
3.1 LOW

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different …

Jul 7, 2026
CVE-2026-55592
3.9 LOW

Dashy is a self-hostable personal dashboard. Prior to 4.3.7, Dashy's workspace view trusts the url query parameter and assigns it directly to an iframe source …

Jul 7, 2026
CVE-2026-14935
3.7 LOW

A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers …

Jul 7, 2026
CVE-2026-48588
3.1 LOW

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when …

Jul 7, 2026
CVE-2026-42201
3.3 LOW

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, database credential fields (redis_password, keydb_password, dragonfly_password, clickhouse_admin_user, clickhouse_admin_password, postgres_user, …

Jul 7, 2026
CVE-2026-27844
2.7 LOW

Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by …

Jul 7, 2026
CVE-2026-27790
2.7 LOW

Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by sending specific requests, resulting in a temporary …

Jul 7, 2026
CVE-2026-42172
3.1 LOW

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Sanctum API tokens did not expire, allowing a leaked …

Jul 7, 2026
CVE-2026-42145
3.1 LOW

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the file upload endpoint (app/Http/Controllers/UploadController.php) for database backup restore …

Jul 7, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.