CVE Database

48241+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-90707
8.3 HIGH

A security flaw has been discovered in Open5GS up to 2.7.x. Affected is the function amf_nnrf_try_old_amf_discovery_fallback of the file src/amf/nnrf-handler.c of the component Old AMF …

Sep 14, 2026
CVE-2026-8821
7.1 HIGH

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing …

Sep 14, 2026
CVE-2026-89180
7.5 HIGH

EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

Sep 14, 2026
CVE-2026-87779
7.5 HIGH

Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard length (not 16/24/32 bytes) is configured, Syncope will pad …

Sep 14, 2026
CVE-2026-90894
7.8 HIGH

Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group. …

Sep 14, 2026
CVE-2026-90701
7.3 HIGH

A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. The affected element is an unknown function of the file listdoctor.php. Performing a manipulation of …

Sep 14, 2026
CVE-2026-72524
8.8 HIGH

Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access or modify data they are not authorized to. This …

Sep 14, 2026
CVE-2026-90691
8.3 HIGH

A security vulnerability has been detected in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is the function FileOperationsManager of the file hexstrike_server.py of …

Sep 14, 2026
CVE-2026-90690
7.3 HIGH

A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected element is the function subprocess.Popen of the file hexstrike_server.py of the …

Sep 14, 2026
CVE-2026-90689
8.8 HIGH

A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthWhiteUser. Performing a manipulation of the argument webAuthWhiteUserIndex results in stack-based …

Sep 14, 2026
CVE-2026-82794
8.8 HIGH

SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by …

Sep 14, 2026
CVE-2026-82793
7.2 HIGH

Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file …

Sep 14, 2026
CVE-2026-82791
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter …

Sep 14, 2026
CVE-2026-82789
8.8 HIGH

An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by …

Sep 14, 2026
CVE-2026-82780
8.8 HIGH

Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uploaded by a remote authenticated attacker, …

Sep 14, 2026
CVE-2026-82779
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series. If this vulnerability is exploited, an …

Sep 14, 2026
CVE-2026-82777
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an …

Sep 14, 2026
CVE-2026-82774
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. …

Sep 14, 2026
CVE-2026-82772
8.8 HIGH

Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program …

Sep 14, 2026
CVE-2026-82770
8.8 HIGH

Buffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program …

Sep 14, 2026
CVE-2026-82768
8.1 HIGH

Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who …

Sep 14, 2026
CVE-2026-82766
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If this vulnerability is exploited, an arbitrary OS …

Sep 14, 2026
CVE-2026-82765
8.1 HIGH

Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be …

Sep 14, 2026
CVE-2026-82762
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If …

Sep 14, 2026
CVE-2026-68955
7.8 HIGH

The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when …

Sep 14, 2026
CVE-2023-50461
8.8 HIGH

An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated …

Sep 14, 2026
CVE-2023-46273
8.8 HIGH

Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.

Sep 14, 2026
CVE-2023-45858
8.6 HIGH

A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.

Sep 14, 2026
CVE-2023-32803
7.5 HIGH

The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue …

Sep 14, 2026
CVE-2023-28148
7.2 HIGH

A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.

Sep 14, 2026
CVE-2026-90620
7.3 HIGH

A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is an unknown function of the file hexstrike_server.py of the component …

Sep 14, 2026
CVE-2026-90619
7.3 HIGH

A vulnerability has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. Impacted is an unknown function of the file hexstrike_server.py of the component Execute …

Sep 14, 2026
CVE-2026-90618
7.3 HIGH

A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the function LocalRuntime.execute_command of the file runtime/runtime.py of the component LocalRuntime. …

Sep 14, 2026
CVE-2026-90617
7.3 HIGH

A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This vulnerability affects the function run_task of the file interface/main.py of the component MCP HTTP …

Sep 14, 2026
CVE-2026-33963
7.5 HIGH

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs …

Sep 14, 2026
CVE-2026-31278
7.7 HIGH

An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service …

Sep 14, 2026
CVE-2026-23789
7.8 HIGH

An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, …

Sep 14, 2026
CVE-2026-90603
7.3 HIGH

A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component …

Sep 13, 2026
CVE-2026-90601
7.3 HIGH

A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The …

Sep 13, 2026
CVE-2026-15891
7.5 HIGH

The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the …

Sep 13, 2026
CVE-2026-90593
7.3 HIGH

A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width …

Sep 13, 2026
CVE-2026-88802
7.5 HIGH

The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or …

Sep 13, 2026
CVE-2026-88793
8.8 HIGH

The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a …

Sep 13, 2026
CVE-2026-85129
8.8 HIGH

The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the …

Sep 13, 2026
CVE-2026-74933
8.8 HIGH

The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored …

Sep 13, 2026
CVE-2026-37008
8.1 HIGH

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module …

Sep 13, 2026
CVE-2026-36453
7.4 HIGH

Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.

Sep 13, 2026
CVE-2026-29811
7.7 HIGH

CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") …

Sep 13, 2026
CVE-2026-90579
7.3 HIGH

A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key of the file core/cat/factory/custom_auth_handler.py. The manipulation of …

Sep 13, 2026
CVE-2026-90566
7.3 HIGH

A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the …

Sep 13, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.