CVE Database

60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8122
5.9 MEDIUM

The WSO2 Identity Server fails to enforce a default expiry time for SMS One-Time Passwords (OTPs) used in multi-factor authentication (MFA). This allows unused OTPs …

Oct 8, 2026
CVE-2026-94154
6.1 MEDIUM

The Aurora Heatmap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.7.2 due …

Oct 8, 2026
CVE-2026-17538
5.4 MEDIUM

The LatePoint - Appointment Booking & Reservation plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.6.9. This …

Oct 8, 2026
CVE-2026-107315
5.3 MEDIUM

pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.4 through 42.7.13 pads a value that is shorter than its declared length with bytes left in its send …

Oct 8, 2026
CVE-2026-107314
5.9 MEDIUM

pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13 enforce no restriction when the requireAuth connection property excludes all six authentication methods the driver knows, …

Oct 7, 2026
CVE-2026-107285
5.9 MEDIUM

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, a proxied ws …

Oct 7, 2026
CVE-2026-105820
5.4 MEDIUM

Vault's ACL policy cache allowed namespace traversal when policy names contained path traversal constructs. This may allow a token assigned specially crafted policy names to …

Oct 7, 2026
CVE-2026-105818
5.9 MEDIUM

Vault's PKI secrets engine ACME server did not restrict certificate identities that ACME challenges do not validate when issuing certificates under the default directory policy. …

Oct 7, 2026
CVE-2026-76286
5.3 MEDIUM

In Splunk MCP Server versions below 1.2.1, Splunk MCP Server could send the Splunk platform authentication token of a user who runs a custom Application …

Oct 7, 2026
CVE-2026-76280
6.3 MEDIUM

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, an authenticated user who does …

Oct 7, 2026
CVE-2026-76279
4.3 MEDIUM

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the run_collect capability could use the collect Search …

Oct 7, 2026
CVE-2026-76278
4.3 MEDIUM

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the edit_spl2_module_permissions capability could use the affected Representational State …

Oct 7, 2026
CVE-2026-76277
4.1 MEDIUM

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the edit_user capability could create a native Splunk …

Oct 7, 2026
CVE-2026-76276
4.3 MEDIUM

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could retrieve original …

Oct 7, 2026
CVE-2026-76275
4.3 MEDIUM

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could access search …

Oct 7, 2026
CVE-2026-76274
6.5 MEDIUM

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could redirect an outbound request from …

Oct 7, 2026
CVE-2026-76273
4.3 MEDIUM

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the run_collect capability could use the collect Search …

Oct 7, 2026
CVE-2026-76272
4.3 MEDIUM

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could cause Splunk …

Oct 7, 2026
CVE-2026-76271
6.5 MEDIUM

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause a …

Oct 7, 2026
CVE-2026-76270
6.5 MEDIUM

In Splunk Enterprise versions below 10.4.3, a user that holds a role with the list_spl2_modules capability could use SQL injection in SPL2 module filtering to …

Oct 7, 2026
CVE-2026-76269
6.5 MEDIUM

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could use a …

Oct 7, 2026
CVE-2026-76267
4.3 MEDIUM

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could inject forged entries into the …

Oct 7, 2026
CVE-2026-76265
6.5 MEDIUM

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, a user who does not …

Oct 7, 2026
CVE-2026-76264
4.3 MEDIUM

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could create or …

Oct 7, 2026
CVE-2026-1403
6.5 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that when importing …

Oct 7, 2026
CVE-2026-107229
4.0 MEDIUM

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.16.0 until 3.0.14, ThreadSafeCookieStore incompletely validates cookie …

Oct 7, 2026
CVE-2026-107228
6.8 MEDIUM

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store …

Oct 7, 2026
CVE-2026-107353
6.5 MEDIUM

traverse (npm) versions 0.3.6 through 0.3.9, 0.4.0 through 0.4.6, 0.5.0 through 0.5.2, and 0.6.0 through 0.6.11 allow prototype pollution through set(). When the path passed …

Oct 7, 2026
CVE-2026-107176
6.8 MEDIUM

A flaw was found in the cluster-samples-operator. The RBAC Role coreos-pull-secret-reader in namespace openshift-config grants get, list, and watch permissions on all Secret resources without …

Oct 7, 2026
CVE-2026-107313
4.2 MEDIUM

pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.4 and 42.7.5 can send the previous contents of the GSS send buffer in place of the first part …

Oct 7, 2026
CVE-2026-107225
6.5 MEDIUM

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.0 to 2.11.0, GetStyle's fill, border, and font extraction predicates check …

Oct 7, 2026
CVE-2026-107224
6.5 MEDIUM

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, a Zip64 uncompressed size with the high bit …

Oct 7, 2026
CVE-2026-107222
6.5 MEDIUM

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.7.0 to 2.11.0, conditional-format extraction indexes required child slices or dereferences …

Oct 7, 2026
CVE-2026-107221
6.5 MEDIUM

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0, checkRow sizes its target cell slice from the …

Oct 7, 2026
CVE-2026-107220
6.5 MEDIUM

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.7.1 to 2.11.0, mergeCellsParser leaves the cached rectangle empty for an …

Oct 7, 2026
CVE-2026-107218
5.3 MEDIUM

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.10.1 to 2.11.0, RIGHT validates the requested length with UTF-16 code-unit …

Oct 7, 2026
CVE-2026-106067
6.3 MEDIUM

A heap-based buffer overflow was found in GIMP’s Hot color filter plug-in. For very large images, a pixel buffer is allocated using overflowing 32-bit width …

Oct 7, 2026
CVE-2026-106066
6.3 MEDIUM

A heap-based buffer overflow was found in GIMP’s raw data export plug-in. When exporting very large images, g_malloc() sizing based on overflowing width * height …

Oct 7, 2026
CVE-2026-76488
6.5 MEDIUM

A vulnerability in the export policies functionality of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to access sensitive files on …

Oct 7, 2026
CVE-2026-76452
4.9 MEDIUM

A vulnerability in the web-based management interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an authenticated, remote attacker …

Oct 7, 2026
CVE-2026-76437
4.9 MEDIUM

A vulnerability in the web-based user interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an authenticated, remote attacker …

Oct 7, 2026
CVE-2026-20321
6.5 MEDIUM

A vulnerability in the web-based management API for Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to execute arbitrary commands as …

Oct 7, 2026
CVE-2026-20173
5.8 MEDIUM

A vulnerability in Cisco NX-OS Software could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of service (DoS) condition. This vulnerability …

Oct 7, 2026
CVE-2026-20038
5.8 MEDIUM

A vulnerability in the endpoint group (EPG) contract functionality of Cisco Nexus 9000 Series Fabric Switches in ACI Mode could allow an unauthenticated, remote attacker …

Oct 7, 2026
CVE-2026-20032
4.4 MEDIUM

A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, local attacker with low privileges to escape the Python sandbox and …

Oct 7, 2026
CVE-2026-106065
6.3 MEDIUM

A heap-based buffer overflow was found in GIMP’s PCX export plug-in. For images with extremely large width and height, buffer allocation uses overflowing 32-bit width …

Oct 7, 2026
CVE-2026-101886
4.0 MEDIUM

Cisco Jabber for Android (com.cisco.im) before 15.3.1.311364 contains a path traversal vulnerability that allows a malicious app with no permissions to write attacker-controlled files into …

Oct 7, 2026
CVE-2026-107273
4.3 MEDIUM

Gophish 0.11.0 through 0.12.1 contains a server-side request forgery vulnerability that allows authenticated low-privileged users to reach loopback and private hosts via POST /api/import/site. Attackers …

Oct 7, 2026
CVE-2026-107272
4.7 MEDIUM

Gophish through 0.12.1 contains stored and reflected cross-site scripting vulnerabilities that allow attackers to inject script by returning malicious SMTP server error messages. Attackers controlling …

Oct 7, 2026
CVE-2026-107271
5.3 MEDIUM

Gophish through 0.12.1 contains a rate limit bypass vulnerability that allows unauthenticated attackers to evade /login throttling by spoofing X-Forwarded-For or X-Real-IP headers. Attackers can …

Oct 7, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.