CVE Database

60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-25263
6.6 MEDIUM

Memory corruption while processing IOCTL command called from user space to the kernel with invalid parameters.

Oct 6, 2026
CVE-2026-97300
6.5 MEDIUM

Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions.

Oct 6, 2026
CVE-2026-39599
4.3 MEDIUM

Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions.

Oct 6, 2026
CVE-2026-32582
6.5 MEDIUM

Contributor Broken Access Control in IATO MCP <= 1.11.0 versions.

Oct 6, 2026
CVE-2026-32576
6.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in ZWEISCHNEIDER Faktur Pro for WooCommerce woorechnung allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Faktur Pro …

Oct 6, 2026
CVE-2026-105775
4.3 MEDIUM

A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component Completions …

Oct 6, 2026
CVE-2026-105708
4.3 MEDIUM

A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component …

Oct 6, 2026
CVE-2026-105707
5.3 MEDIUM

A security vulnerability has been detected in uptrace up to 2.1.0-beta.8. Affected by this vulnerability is the function Login of the file pkg/org/user_handler.go. The manipulation …

Oct 6, 2026
CVE-2026-105706
4.3 MEDIUM

A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected is an unknown function. Executing a manipulation can lead to cross-site request forgery. …

Oct 6, 2026
CVE-2026-105705
4.3 MEDIUM

A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file Admin/add_drug.php. Performing a manipulation results …

Oct 6, 2026
CVE-2026-105703
4.7 MEDIUM

A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file …

Oct 6, 2026
CVE-2026-105621
5.4 MEDIUM

A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component Financial …

Oct 6, 2026
CVE-2026-105610
4.7 MEDIUM

A vulnerability was found in chillzhuang SpringBlade up to 5.0.1. The impacted element is an unknown function of the file blade-service/blade-system/src/main/java/org/springblade/system/controller/ParamController.java of the component Parameter …

Oct 6, 2026
CVE-2026-105573
4.3 MEDIUM

A vulnerability was found in newbee-ltd newbee-mall up to 2.7.5. This impacts an unknown function of the file /jshERP-boot/accountHead/updateAccountHeadAndDetail of the component Shopping Cart Quantity …

Oct 6, 2026
CVE-2026-105572
4.3 MEDIUM

A vulnerability has been found in PickMall Lilishop up to 4.2.4. This affects an unknown function of the file /buyer/trade/receipt of the component Buyer Invoice …

Oct 6, 2026
CVE-2026-105487
6.3 MEDIUM

A vulnerability was found in yogeshojha reNgine up to 2.2.0. Affected by this vulnerability is the function subdomain_discovery of the file web/reNgine/tasks.py of the component …

Oct 6, 2026
CVE-2026-104380
5.3 MEDIUM

Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one. On HTTP/2 and …

Oct 6, 2026
CVE-2026-104044
6.2 MEDIUM

A flaw was found in sssd. A local attacker can trigger a Denial of Service (DoS) by sending a specially crafted Pluggable Authentication Module (PAM) …

Oct 6, 2026
CVE-2026-104043
5.5 MEDIUM

A flaw was found in SSSD. A local attacker with access to the Name Service Switch (NSS) responder UNIX socket can trigger an integer underflow …

Oct 6, 2026
CVE-2026-104042
5.5 MEDIUM

A flaw was found in sssd. A local attacker can cause a Denial of Service (DoS) by sending a crafted Pluggable Authentication Module (PAM) request …

Oct 6, 2026
CVE-2026-104041
5.5 MEDIUM

A flaw was found in SSSD. An unprivileged local user can repeatedly request lookups for nonexistent entries through the Name Service Switch (NSS) responder. Because …

Oct 6, 2026
CVE-2026-104040
4.4 MEDIUM

A flaw was found in SSSD. When configured with the Entra ID identity provider, input lookup names containing single quotes are not properly escaped before …

Oct 6, 2026
CVE-2026-104039
4.7 MEDIUM

A flaw was found in SSSD. A local user can cause a denial of service (DoS) by disrupting system authentication services. When handling Generic Security …

Oct 6, 2026
CVE-2026-92821
6.8 MEDIUM

A flaw was found in SSSD. When configured to evaluate password expiration warnings before restrictive access rules in LDAP (Lightweight Directory Access Protocol) environments, an …

Oct 6, 2026
CVE-2026-105472
6.3 MEDIUM

A weakness has been identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. The affected element is an unknown function of the file book.php of the component …

Oct 6, 2026
CVE-2026-104038
5.9 MEDIUM

A flaw was found in sssd. A remote attacker can cause a denial of service (DoS) by submitting a certificate that lacks an expected Security …

Oct 6, 2026
CVE-2026-104037
5.5 MEDIUM

A flaw was found in SSSD. A local attacker can exploit this issue by sending a specially crafted request with an invalid packet length to …

Oct 6, 2026
CVE-2026-104036
5.8 MEDIUM

A flaw was found in SSSD's NFS idmap plugin. When retrieving cached user or group names, the plugin detects if an entry exceeds the destination …

Oct 6, 2026
CVE-2026-104035
5.5 MEDIUM

A flaw was found in SSSD. An issue in the Kerberos Credential Manager (KCM) responder allows a local user to cause a Denial of Service …

Oct 6, 2026
CVE-2026-104034
4.7 MEDIUM

A flaw was found in SSSD. A use-after-free vulnerability exists in the Kerberos Credential Manager (KCM) responder during Kerberos ticket-granting ticket (TGT) renewal, where a …

Oct 6, 2026
CVE-2026-104033
5.4 MEDIUM

A flaw was found in SSSD. When configured to enforce account expiration using LDAP (Lightweight Directory Access Protocol) shadow attributes, SSSD fails to treat an …

Oct 6, 2026
CVE-2026-104032
5.5 MEDIUM

A flaw was found in SSSD. An unprivileged local user can repeatedly request master automount map updates through the autofs responder due to missing authorization …

Oct 6, 2026
CVE-2026-104031
5.5 MEDIUM

A flaw was found in SSSD. In configurations where the autofs responder service is enabled, memory allocated during successful request processing is not released until …

Oct 6, 2026
CVE-2026-105785
4.8 MEDIUM

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to Joplin Server 3.7.2, packages/server/src/models/TokenModel.ts stores CSRF, account-confirmation, …

Oct 6, 2026
CVE-2026-105784
4.6 MEDIUM

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, selecting a note containing a jsoncanvas …

Oct 6, 2026
CVE-2026-105760
5.3 MEDIUM

vLLM is an inference and serving engine for large language models. Prior to 0.30.0, a caller can use the request-level media_io_kwargs field to select the …

Oct 5, 2026
CVE-2026-105759
5.9 MEDIUM

vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the Rust frontend's track_http_metrics middleware records the raw HTTP method token …

Oct 5, 2026
CVE-2026-105758
5.3 MEDIUM

vLLM is an inference and serving engine for large language models. From 0.24.0 until 0.30.0, the Qwen2VLVideoBackend and Qwen3VLVideoBackend classes accept request-level values for the …

Oct 5, 2026
CVE-2026-105757
6.5 MEDIUM

vLLM is an inference and serving engine for large language models. Prior to 0.30.0, structured-output request failures can escape request-scoped validation and reach the EngineCore …

Oct 5, 2026
CVE-2026-105756
6.5 MEDIUM

vLLM is an inference and serving engine for large language models. Prior to 0.30.0, OpenAI-compatible request models accept a non-empty cache_salt value without enforcing the …

Oct 5, 2026
CVE-2026-105755
4.2 MEDIUM

vLLM is an inference and serving engine for large language models. Prior to 0.30.0, flash late-interaction scoring at the /score and /rerank endpoints derives each …

Oct 5, 2026
CVE-2026-105754
6.5 MEDIUM

vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the /inference/v1/generate endpoint in the disaggregated scale-out path accepts caller-supplied tensors …

Oct 5, 2026
CVE-2026-105753
6.5 MEDIUM

vLLM is an inference and serving engine for large language models. Prior to 0.28.0, the default mirrored multimodal LRU cache can commit a media hash …

Oct 5, 2026
CVE-2026-105750
5.9 MEDIUM

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.82.0 until 2.118.1, HTMLBackendOptions(render_page=True) permits file URLs because …

Oct 5, 2026
CVE-2026-105749
6.5 MEDIUM

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.0.0 until 2.131.0, the HTML, JATS, OpenDocument spreadsheet, …

Oct 5, 2026
CVE-2026-105748
4.3 MEDIUM

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.16.0 until 2.131.0, the InputFormat.JSON_DOCLING backend in docling/backend/json/docling_json_backend.py …

Oct 5, 2026
CVE-2026-105747
4.3 MEDIUM

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.131.0, METS-GBS format detection in docling/datamodel/document.py …

Oct 5, 2026
CVE-2026-105745
6.7 MEDIUM

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.27.0 until 2.131.0, Docling plugin factories in docling/models/factories/base_factory.py …

Oct 5, 2026
CVE-2026-105743
4.0 MEDIUM

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.91.0 until 2.132.0, validate_url_safety in docling/backend/utils/image_resource_loader.py validates a …

Oct 5, 2026
CVE-2026-103546
4.3 MEDIUM

In MongoDB Controllers for Kubernetes, insufficient validation of Ops Manager backup configuration may allow a user who can modify an OpsManager custom resource to cause …

Oct 5, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.