CVE Database

10419+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-64541
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket smc_cdc_rx_handler() looks up the connection by …

Jul 27, 2026
CVE-2026-43822
9.8 CRITICAL

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS …

Jul 27, 2026
CVE-2026-43814
9.8 CRITICAL

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS …

Jul 27, 2026
CVE-2026-43812
9.8 CRITICAL

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS …

Jul 27, 2026
CVE-2026-43810
9.8 CRITICAL

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS …

Jul 27, 2026
CVE-2026-43809
9.8 CRITICAL

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app …

Jul 27, 2026
CVE-2026-43807
9.8 CRITICAL

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, …

Jul 27, 2026
CVE-2026-43805
9.8 CRITICAL

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, …

Jul 27, 2026
CVE-2026-43803
9.8 CRITICAL

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma …

Jul 27, 2026
CVE-2026-43802
9.8 CRITICAL

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An …

Jul 27, 2026
CVE-2026-43799
9.8 CRITICAL

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS …

Jul 27, 2026
CVE-2026-43793
9.8 CRITICAL

An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS …

Jul 27, 2026
CVE-2026-43779
9.8 CRITICAL

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may …

Jul 27, 2026
CVE-2026-43778
9.8 CRITICAL

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS …

Jul 27, 2026
CVE-2026-43773
9.8 CRITICAL

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Mounting a …

Jul 27, 2026
CVE-2026-43769
9.8 CRITICAL

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, …

Jul 27, 2026
CVE-2026-43764
9.8 CRITICAL

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app …

Jul 27, 2026
CVE-2026-43757
9.8 CRITICAL

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app …

Jul 27, 2026
CVE-2026-43750
9.8 CRITICAL

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app …

Jul 27, 2026
CVE-2026-43748
9.8 CRITICAL

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be …

Jul 27, 2026
CVE-2026-43730
9.8 CRITICAL

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, …

Jul 27, 2026
CVE-2026-43710
9.8 CRITICAL

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker may …

Jul 27, 2026
CVE-2026-43694
9.8 CRITICAL

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may …

Jul 27, 2026
CVE-2026-43682
9.8 CRITICAL

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user …

Jul 27, 2026
CVE-2026-39873
9.8 CRITICAL

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Connecting to a …

Jul 27, 2026
CVE-2026-28982
9.8 CRITICAL

A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user …

Jul 27, 2026
CVE-2026-28928
9.8 CRITICAL

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS …

Jul 27, 2026
CVE-2026-28911
9.8 CRITICAL

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able …

Jul 27, 2026
CVE-2026-55579
9.8 CRITICAL

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password …

Jul 27, 2026
CVE-2026-48030
9.9 CRITICAL

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the …

Jul 27, 2026
CVE-2026-17552
9.1 CRITICAL

Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call. When the rewrite base is a plain …

Jul 27, 2026
CVE-2026-63077
9.8 CRITICAL KEV

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Jul 27, 2026
CVE-2026-17191
9.1 CRITICAL

An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may …

Jul 27, 2026
CVE-2026-66395
9.6 CRITICAL

SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting …

Jul 27, 2026
CVE-2026-16812
10.0 CRITICAL KEV

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO …

Jul 27, 2026
CVE-2025-50455
9.1 CRITICAL

SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input …

Jul 27, 2026
CVE-2026-59550
9.3 CRITICAL

Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.

Jul 27, 2026
CVE-2026-59549
9.3 CRITICAL

Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.

Jul 27, 2026
CVE-2026-59538
9.3 CRITICAL

Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.

Jul 27, 2026
CVE-2026-59533
9.3 CRITICAL

Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.

Jul 27, 2026
CVE-2026-59527
9.3 CRITICAL

Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

Jul 27, 2026
CVE-2026-65879
9.8 CRITICAL

Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers …

Jul 27, 2026
CVE-2026-61511
9.8 CRITICAL

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote …

Jul 27, 2026
CVE-2026-58662
9.1 CRITICAL

Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended …

Jul 27, 2026
CVE-2026-58023
9.1 CRITICAL

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes …

Jul 27, 2026
CVE-2026-55971
9.8 CRITICAL

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which …

Jul 27, 2026
CVE-2026-48144
9.1 CRITICAL

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade …

Jul 27, 2026
CVE-2026-64535
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnerability testing: When data …

Jul 27, 2026
CVE-2026-64534
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path In nvmet_tcp_try_recv_ddgst(), when a data digest …

Jul 27, 2026
CVE-2026-14289
9.0 CRITICAL

The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a …

Jul 27, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.