CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-67873

A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment …

Aug 6, 2026
CVE-2026-67872

An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queue resize handling

Aug 6, 2026
CVE-2026-67871

Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddNodes, address_space_bs.c, sopc_node_mgt_helper_internal.c, and toolkit_test_server

Aug 6, 2026
CVE-2026-67870

In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with …

Aug 6, 2026
CVE-2026-67531

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances to …

Aug 6, 2026
CVE-2026-52466

Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after …

Aug 6, 2026
CVE-2026-19028

H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size …

Aug 6, 2026
CVE-2026-19027

The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_atomic functions in H5Znbit.c in HDF5 through 2.3.0 advance a read index into the compressed chunk buffer without bounding it against …

Aug 6, 2026
CVE-2023-54389

Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

Aug 6, 2026
CVE-2023-54388

Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

Aug 6, 2026
CVE-2023-54387

Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

Aug 6, 2026
CVE-2023-54386

Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

Aug 6, 2026
CVE-2023-54385

Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

Aug 6, 2026
CVE-2023-54384

Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

Aug 6, 2026
CVE-2023-54383

Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

Aug 6, 2026
CVE-2023-54382

Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

Aug 6, 2026
CVE-2023-54381

Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

Aug 6, 2026
CVE-2023-54380

Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

Aug 6, 2026
CVE-2023-54379

Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

Aug 6, 2026
CVE-2023-54378

Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

Aug 6, 2026
CVE-2023-54377

Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

Aug 6, 2026
CVE-2023-54376

Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

Aug 6, 2026
CVE-2023-54375

Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

Aug 6, 2026
CVE-2026-67867

Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Alarm/Conditions wrapper when processing PublishResponse EventNotificationList …

Aug 5, 2026
CVE-2026-67866

Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse and SOPC_StaMac_NewDeleteMonitoredItems in the client …

Aug 5, 2026
CVE-2026-19026

H5Z__filter_nbit in H5Znbit.c in HDF5 through 2.3.0 dereferences cd_values[0] through cd_values[4] without validating that cd_values is non-NULL or that cd_nelmts is at least 5, the …

Aug 5, 2026
CVE-2026-19025

H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset's stored chunk-layout dimensionality matches its dataspace rank when an existing dataset …

Aug 5, 2026
CVE-2026-19024

NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.1.1 allows attackers to cause a denial of service via a dataset whose version 1 or 2 …

Aug 5, 2026
CVE-2026-19023

Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.1.1 allows attackers to cause a denial of service via a …

Aug 5, 2026
CVE-2026-67865

S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handling. This allows a remote attacker to cause a denial of service

Aug 5, 2026
CVE-2026-67864

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logic component

Aug 5, 2026
CVE-2025-63823

My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user …

Aug 5, 2026
CVE-2025-63822

SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized …

Aug 5, 2026
CVE-2026-71309

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rclone serve restic does …

Aug 5, 2026
CVE-2026-15996

A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause excessive CPU consumption and exhaust the pool …

Aug 5, 2026
CVE-2026-68746

Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to obtain full access to a Livebook server that enforces identity …

Aug 5, 2026
CVE-2026-66885

Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's browser session under the attacker's own Livebook Teams identity. When …

Aug 5, 2026
CVE-2026-66881

Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with attacker-controlled content to an arbitrary path. A .livemd notebook …

Aug 5, 2026
CVE-2026-66298

Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger session-wide keyboard shortcuts, including forced evaluation of all cells and runtime …

Aug 5, 2026
CVE-2026-66297

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev livebook allows command injection into generated deployment setup commands. …

Aug 5, 2026
CVE-2026-55523

PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.web_crawl() function is vulnerable to server-side request forgery. While it validates the initially …

Aug 5, 2026
CVE-2026-17556

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including …

Aug 5, 2026
CVE-2026-70445

Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

Aug 5, 2026
CVE-2026-70438

A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored …

Aug 5, 2026
CVE-2026-70437

Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer …

Aug 5, 2026
CVE-2026-70436

Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when …

Aug 5, 2026
CVE-2026-70435

A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials …

Aug 5, 2026
CVE-2026-70434

A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs …

Aug 5, 2026
CVE-2026-70433

Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

Aug 5, 2026
CVE-2026-70430

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming …

Aug 5, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.