CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-34854
6.6 MEDIUM

HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.

Sep 14, 2026
CVE-2023-29377
6.6 MEDIUM

An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is …

Sep 14, 2026
CVE-2026-90621
6.3 MEDIUM

A vulnerability was identified in ipa-lab HackingBuddyGPT up to 0.5.0. This affects the function ssh_run_command of the file src/hackingBuddyGPT/extensions/ssh_run_command.py. Such manipulation leads to os command …

Sep 14, 2026
CVE-2026-90615
4.3 MEDIUM

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /subject1.php. Such manipulation …

Sep 14, 2026
CVE-2026-90614
6.3 MEDIUM

A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the …

Sep 14, 2026
CVE-2026-33964
6.4 MEDIUM

An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occurs when a malformed message is sent …

Sep 14, 2026
CVE-2026-33957
4.2 MEDIUM

An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory from the custos_iwc device enables out-of-bounds read and …

Sep 14, 2026
CVE-2026-23792
4.0 MEDIUM

An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W1000, …

Sep 14, 2026
CVE-2026-23791
4.2 MEDIUM

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. An out-of-bounds write vulnerability …

Sep 14, 2026
CVE-2026-23790
4.2 MEDIUM

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in …

Sep 14, 2026
CVE-2026-23788
4.2 MEDIUM

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR driver (due …

Sep 14, 2026
CVE-2026-23787
4.2 MEDIUM

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A Use-After-Free in the …

Sep 14, 2026
CVE-2025-68624
4.3 MEDIUM

N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user to send outbound email using MAIL FROM addresses …

Sep 14, 2026
CVE-2025-63842
5.4 MEDIUM

A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote authenticated user to execute arbitrary JavaScript …

Sep 14, 2026
CVE-2024-53922
5.7 MEDIUM

An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack of a length check …

Sep 14, 2026
CVE-2022-42917
6.7 MEDIUM

In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config …

Sep 14, 2026
CVE-2026-90600
6.3 MEDIUM

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipulation of the …

Sep 13, 2026
CVE-2026-15892
5.3 MEDIUM

The mcumgr SMP settings-management group handlers settings_mgmt_read(), settings_mgmt_write(), and settings_mgmt_delete() in subsys/mgmt/mcumgr/grp/settings_mgmt/src/settings_mgmt.c allocate a key_name buffer (and, for read, a data buffer) via k_malloc() when …

Sep 13, 2026
CVE-2026-90599
4.3 MEDIUM

A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affects an unknown function of the file includes/process.php. Executing a manipulation can lead …

Sep 13, 2026
CVE-2026-90598
6.3 MEDIUM

A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. The impacted element is the function UserController.updateUser of the file UserController.java. Performing a manipulation of …

Sep 13, 2026
CVE-2026-90597
6.3 MEDIUM

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/sup_edit1.php. Such …

Sep 13, 2026
CVE-2026-90596
6.5 MEDIUM

A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer …

Sep 13, 2026
CVE-2026-90595
6.3 MEDIUM

A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The manipulation results in missing …

Sep 13, 2026
CVE-2026-90594
6.3 MEDIUM

A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function PermissionService.checkUserPermission of the file /rpc/service/PermissionService.java of the component Permission Service. The manipulation …

Sep 13, 2026
CVE-2026-90584
5.3 MEDIUM

A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFrameContinuousAndNonFin of the file Draft_6455.java of the component …

Sep 13, 2026
CVE-2026-89050
4.3 MEDIUM

The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling …

Sep 13, 2026
CVE-2026-36989
5.8 MEDIUM

A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php.

Sep 13, 2026
CVE-2026-90583
4.3 MEDIUM

A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the …

Sep 13, 2026
CVE-2026-90582
5.3 MEDIUM

A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipulation …

Sep 13, 2026
CVE-2026-90581
6.3 MEDIUM

A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument …

Sep 13, 2026
CVE-2026-90580
6.3 MEDIUM

A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint. …

Sep 13, 2026
CVE-2026-29812
4.3 MEDIUM

CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.

Sep 13, 2026
CVE-2026-29810
4.3 MEDIUM

CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.

Sep 13, 2026
CVE-2026-90578
5.3 MEDIUM

A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gf_list_count of the file utils/list.c of the component …

Sep 13, 2026
CVE-2026-90577
5.3 MEDIUM

A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. …

Sep 13, 2026
CVE-2025-70819
6.3 MEDIUM

Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as volumes: - ../../../../../../../etc:/h_etc:rw in a compose file.

Sep 13, 2026
CVE-2020-15875
5.0 MEDIUM

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a …

Sep 13, 2026
CVE-2026-90574
6.3 MEDIUM

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/emp_transac.php?action=add. The manipulation of …

Sep 13, 2026
CVE-2026-90572
4.7 MEDIUM

A vulnerability was determined in davenardella snap7 up to 1.4.3. The affected element is the function TSnap7MicroClient::opUpload of the file src/core/s7_micro_client.cpp. Executing a manipulation of …

Sep 13, 2026
CVE-2026-90571
4.3 MEDIUM

A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown function of the file xmall-manager-web/src/main/webapp/WEB-INF/jsp/order-print.jsp of the component Order Printing. Performing …

Sep 13, 2026
CVE-2026-90565
5.3 MEDIUM

A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is an unknown function of the file dashboard.php. Performing a manipulation of …

Sep 13, 2026
CVE-2026-90527
4.3 MEDIUM

A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admin/src/views/message/message/index.vue of the component Add Message API. …

Sep 13, 2026
CVE-2026-90525
6.3 MEDIUM

A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php. Executing a manipulation of …

Sep 13, 2026
CVE-2026-90782
5.3 MEDIUM

S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificationList. Attackers …

Sep 13, 2026
CVE-2026-90781
4.4 MEDIUM

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field …

Sep 13, 2026
CVE-2026-90521
6.3 MEDIUM

A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. This issue affects some unknown processing of the file MenpiaodingdanController.java of the component CRUD. The …

Sep 13, 2026
CVE-2026-90520
6.3 MEDIUM

A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization Interceptor. …

Sep 13, 2026
CVE-2026-90519
6.3 MEDIUM

A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the …

Sep 13, 2026
CVE-2026-90775
6.5 MEDIUM

PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious …

Sep 13, 2026
CVE-2026-90518
6.3 MEDIUM

A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of …

Sep 13, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.