CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-16148
4.6 MEDIUM

The ITE it82xx2 USB device-controller driver initialized its bus-suspend detection work with k_work_init_delayable(&priv->suspended_work, suspended_handler) inside it82xx2_enable() (the driver's .enable op) in drivers/usb/udc/udc_it82xx2.c. This work item …

Sep 14, 2026
CVE-2026-16147
6.8 MEDIUM

The ITE IT82xx2 USB device-controller driver (drivers/usb/udc/udc_it82xx2.c) mishandles multi-packet OUT transfers on non-control endpoints. In work_handler_out() the active transfer buffer is obtained with udc_buf_peek() (which …

Sep 14, 2026
CVE-2026-15924
5.9 MEDIUM

Zephyr's TLS socket layer in subsys/net/lib/sockets/sockets_tls.c keeps a single process-global array, client_cache, of cached client sessions that is shared by every TLS socket context. The …

Sep 14, 2026
CVE-2026-15887
5.4 MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests.

Sep 14, 2026
CVE-2026-15634
6.5 MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of …

Sep 14, 2026
CVE-2026-15412
6.5 MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an …

Sep 14, 2026
CVE-2026-15396
6.5 MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of …

Sep 14, 2026
CVE-2026-90812
4.3 MEDIUM

A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0. This impacts the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell …

Sep 14, 2026
CVE-2026-90810
6.3 MEDIUM

A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the …

Sep 14, 2026
CVE-2026-90808
6.3 MEDIUM

A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation …

Sep 14, 2026
CVE-2026-89021
6.9 MEDIUM

MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container …

Sep 14, 2026
CVE-2026-89020
4.3 MEDIUM

MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated …

Sep 14, 2026
CVE-2026-82519
4.3 MEDIUM

Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely …

Sep 14, 2026
CVE-2026-19543
6.2 MEDIUM

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and …

Sep 14, 2026
CVE-2026-18515
4.3 MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when …

Sep 14, 2026
CVE-2026-18151
4.2 MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition during the WebSocket …

Sep 14, 2026
CVE-2026-15893
6.5 MEDIUM

net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reachable_time as min_reachable + sys_rand32_get() % (max_reachable - min_reachable), where min_reachable = base/2 and max_reachable …

Sep 14, 2026
CVE-2026-91081
5.8 MEDIUM

Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public …

Sep 14, 2026
CVE-2026-91021
5.4 MEDIUM

Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renderer for webView notes due to improper HTML escaping …

Sep 14, 2026
CVE-2026-90807
6.3 MEDIUM

A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the file src/modules/agent-to-agent/agent-route.ts of the component Attachment Handler. …

Sep 14, 2026
CVE-2026-90806
6.3 MEDIUM

A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the component Bulk …

Sep 14, 2026
CVE-2026-57581
5.3 MEDIUM

DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applications with configured file upload storage allow unauthenticated users …

Sep 14, 2026
CVE-2026-57570
6.5 MEDIUM

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 …

Sep 14, 2026
CVE-2026-55847
6.1 MEDIUM

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js helper at allure-generator/src/main/javascript/helpers/ansi.js passes attacker-influenced …

Sep 14, 2026
CVE-2026-55846
6.2 MEDIUM

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP server started by allure serve …

Sep 14, 2026
CVE-2026-55832
6.1 MEDIUM

Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2, the tract-onnx crate passes the attacker-controlled external_data location …

Sep 14, 2026
CVE-2026-54723
6.5 MEDIUM

devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a server configured with the primary …

Sep 14, 2026
CVE-2026-54181
5.4 MEDIUM

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 …

Sep 14, 2026
CVE-2026-54177
6.6 MEDIUM

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 …

Sep 14, 2026
CVE-2026-54176
6.5 MEDIUM

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 …

Sep 14, 2026
CVE-2026-50157
6.5 MEDIUM

Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security …

Sep 14, 2026
CVE-2026-47256
5.3 MEDIUM

OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and …

Sep 14, 2026
CVE-2026-19542
5.6 MEDIUM

Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an …

Sep 14, 2026
CVE-2026-90804
4.8 MEDIUM

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame …

Sep 14, 2026
CVE-2026-90803
5.3 MEDIUM

A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component …

Sep 14, 2026
CVE-2026-90802
4.4 MEDIUM

A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes …

Sep 14, 2026
CVE-2026-90801
5.3 MEDIUM

A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation …

Sep 14, 2026
CVE-2026-90796
6.3 MEDIUM

A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/company/index.php. The manipulation of the argument ID …

Sep 14, 2026
CVE-2026-57497
5.3 MEDIUM

webtransport-go is an implementation of the WebTransport protocol. Prior to 0.11.1, Session.parseNextCapsule() in session.go skips an unknown WebTransport capsule on the HTTP/3 request stream by …

Sep 14, 2026
CVE-2026-55837
6.8 MEDIUM

dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_mcp/oauth/fastapi_app.py exposes GET /dbt_platform_context without authentication …

Sep 14, 2026
CVE-2026-55073
6.2 MEDIUM

WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restrictive url_fetcher and pass attacker-influenced values to HTML.write_pdf() can …

Sep 14, 2026
CVE-2026-53496
5.3 MEDIUM

ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous file and URL loaders can pass attacker-supplied HEIC or AVIF data …

Sep 14, 2026
CVE-2026-15923
4.6 MEDIUM

The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in subsys/sd/sdio.c finishes transfers with a byte-I/O loop that uses size = MIN(remaining, func->cis.max_blk_size) as the per-iteration step. The …

Sep 14, 2026
CVE-2026-90996
4.0 MEDIUM

A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services …

Sep 14, 2026
CVE-2026-90995
5.5 MEDIUM

A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket …

Sep 14, 2026
CVE-2026-90994
4.0 MEDIUM

A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data(). A local client with access to the …

Sep 14, 2026
CVE-2026-90795
4.3 MEDIUM

A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function of the file navbar.php. Executing a manipulation of …

Sep 14, 2026
CVE-2026-90794
6.3 MEDIUM

A vulnerability was found in GPAC up to f1219cde. The affected element is the function gf_sg_script_load of the file scenegraph/vrml_tools.c of the component MP4Box. Performing …

Sep 14, 2026
CVE-2026-90793
5.4 MEDIUM

A vulnerability has been found in GPAC up to f1219cde. Impacted is the function gf_node_get_name of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation …

Sep 14, 2026
CVE-2026-90792
4.3 MEDIUM

A flaw has been found in GPAC up to f1219cde. This issue affects the function gf_node_list_get_child of the file scenegraph/base_scenegraph.c of the component MP4Box. This …

Sep 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.