CVE Database

60452+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-87107
5.4 MEDIUM

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported …

Sep 10, 2026
CVE-2026-87106
6.5 MEDIUM

Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server …

Sep 10, 2026
CVE-2026-89045
4.0 MEDIUM

zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops. Attackers can pass negative length values …

Sep 10, 2026
CVE-2026-89044
6.5 MEDIUM

Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle …

Sep 10, 2026
CVE-2026-88055
5.5 MEDIUM

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.16.1 and earlier, the …

Sep 10, 2026
CVE-2026-88054
5.5 MEDIUM

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Plumbing::DeSerialize in src/lstm/plumbing.cpp rejects excessively large network stacks but accepts a zero-length stack …

Sep 10, 2026
CVE-2026-88028
6.5 MEDIUM

Improper neutralization of special elements in data query logic in the polymorphic relation handling of the MongoDB integration for Laravel can cause a caller-supplied relation …

Sep 10, 2026
CVE-2026-88026
6.5 MEDIUM

Improper neutralization of regular-expression metacharacters in the LINQ query translation component of the MongoDB C# Driver can cause a caller-supplied character sequence to alter a …

Sep 10, 2026
CVE-2026-88050
5.5 MEDIUM

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharcompress.h validates length_ but accepts negative code_ values from a crafted …

Sep 10, 2026
CVE-2026-88049
5.5 MEDIUM

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks to NetworkIO::CopyTimeStepGeneral and NetworkIO::Randomize in src/lstm/networkio.cpp but …

Sep 10, 2026
CVE-2026-88046
5.3 MEDIUM

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone core does not reject …

Sep 10, 2026
CVE-2026-52097
6.8 MEDIUM

An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (url_launcher.dart), OpenFilex.open, localPathRegex (common_patterns.dart) components

Sep 10, 2026
CVE-2026-88940
5.3 MEDIUM

knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host …

Sep 10, 2026
CVE-2026-88938
6.5 MEDIUM

knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent sessions to read source …

Sep 10, 2026
CVE-2026-88015
5.3 MEDIUM

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true …

Sep 10, 2026
CVE-2026-88014
6.3 MEDIUM

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.72.0 until 1.75.1, the archive ZIP backend …

Sep 10, 2026
CVE-2026-88012
5.3 MEDIUM

Traefik is an open source HTTP reverse proxy and load balancer. From 2.8.2 until 2.11.56 and 3.7.12, HTTP/3 entrypoints do not apply entryPoints..transport.respondingTimeouts.readTimeout because the …

Sep 10, 2026
CVE-2026-87913
5.9 MEDIUM

A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source …

Sep 10, 2026
CVE-2026-87912
5.9 MEDIUM

A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1.1.0 might allow remote attackers to obtain the private …

Sep 10, 2026
CVE-2026-81052
6.8 MEDIUM

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with physical access could potentially exploit …

Sep 10, 2026
CVE-2026-81051
6.6 MEDIUM

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Security Version Number Mutable to Older Versions vulnerability. A low privileged attacker with physical access could …

Sep 10, 2026
CVE-2026-81049
4.4 MEDIUM

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability. A high privileged attacker with local access could potentially exploit …

Sep 10, 2026
CVE-2026-88898
6.5 MEDIUM

AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into …

Sep 10, 2026
CVE-2026-88897
5.9 MEDIUM

Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or …

Sep 10, 2026
CVE-2026-88006
6.5 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's OAuth token exchange endpoint issues a session for …

Sep 10, 2026
CVE-2026-88005
6.5 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for …

Sep 10, 2026
CVE-2026-85310
6.5 MEDIUM

import_contacts Path Traversal in Groundhogg <= 4.7.1 versions.

Sep 10, 2026
CVE-2026-81793
6.5 MEDIUM

Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions.

Sep 10, 2026
CVE-2026-81791
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions.

Sep 10, 2026
CVE-2026-81788
6.3 MEDIUM

Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions.

Sep 10, 2026
CVE-2026-81787
6.5 MEDIUM

Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions.

Sep 10, 2026
CVE-2026-81785
6.5 MEDIUM

Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions.

Sep 10, 2026
CVE-2026-81782
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in WP Docs <= 2.3.1 versions.

Sep 10, 2026
CVE-2026-81275
6.5 MEDIUM

Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions.

Sep 10, 2026
CVE-2026-78536
6.5 MEDIUM

Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.

Sep 10, 2026
CVE-2026-66674
5.6 MEDIUM

Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.

Sep 10, 2026
CVE-2026-66632
6.5 MEDIUM

Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1.42.1 versions.

Sep 10, 2026
CVE-2026-15461
5.3 MEDIUM

The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, later drivers/modem/vendor_standalone/hl78xx/) embeds a generic struct gnss_nmea0183_match_data match_data inside struct hl78xx_gnss_data. The generic NMEA0183 match helper (drivers/gnss/gnss_nmea0183_match.c) …

Sep 10, 2026
CVE-2026-88896
5.3 MEDIUM

EspoCRM before 10.0.4 is vulnerable to server-side request forgery. HostCheck::ipAddressIsNotInternal(), which validates outbound URLs to block requests to internal/private IP addresses, strips ::ffff: (IPv4-mapped IPv6) …

Sep 10, 2026
CVE-2026-88894
5.4 MEDIUM

Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target. Unlike the single, bulk, API, accessory, …

Sep 10, 2026
CVE-2026-88892
5.0 MEDIUM

OpenPanel is an analytics platform. In all versions (no patched release available at time of publication), the data importer fetches a caller-supplied URL with plain …

Sep 10, 2026
CVE-2026-88884
5.8 MEDIUM

Renovate is a dependency update automation tool. In versions before 44.3.1 (and Mend Renovate CE/EE images before 15.4.0, mend-renovate-ce Helm chart before 15.4.0, mend-renovate-enterprise-edition Helm …

Sep 10, 2026
CVE-2026-88878
5.3 MEDIUM

Traefik is an HTTP reverse proxy and load balancer. In versions >= v2.8.2 through <= v2.11.55 and >= v3.0.0 through <= v3.7.11, the entryPoints.<name>.transport.respondingTimeouts settings …

Sep 10, 2026
CVE-2026-88875
4.3 MEDIUM

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) incompletely sanitizes sensitive user fields in the APIName=video response. Video rows include columns joined from the video owner's user …

Sep 10, 2026
CVE-2026-88871
4.3 MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) contains a cross-site request forgery vulnerability in the CustomizeUser plugin's plugin/CustomizeUser/setSubscribers.json.php endpoint. The script reads users_id and ExtraSubscribers …

Sep 10, 2026
CVE-2026-88860
6.3 MEDIUM

Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving stale overrides active. Attackers can retain channel-specific …

Sep 10, 2026
CVE-2026-88790
4.8 MEDIUM

A security vulnerability has been detected in proma-ai Proma up to 0.19.37. Affected is the function resolveTargetPath of the file apps/electron/src/main/lib/file-preview-service.ts of the component File …

Sep 10, 2026
CVE-2026-45763
5.9 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, when …

Sep 10, 2026
CVE-2026-12683
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: …

Sep 10, 2026
CVE-2026-12682
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: …

Sep 10, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.