No results found for ""
Try different keywords or check spelling
Search in CVE database, posts & pages • Press ESC to close
Vulnerability Database & Cybersecurity Intelligence Platform
Real-time CVE vulnerability tracking, CVSS scoring, CISA KEV alerts, and EPSS data to protect your infrastructure from emerging threats.
Highest priority threats requiring immediate attention
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not…
Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork…
Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for route matching, but request.url retains…
VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected…
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_? in the UI and GET /resources/:resource/:id/:related/new…
All the tools you need to monitor, analyze, and respond to vulnerabilities
Access 276,476+ vulnerabilities with CVSS scores, technical details, and affected products.
Prioritize vulnerabilities with CVSS v3.1 severity scores and EPSS exploit probability data.
Track vulnerabilities by vendor: Microsoft, Google, Apple, Linux, and thousands more.
Search vulnerabilities by specific product and get alerts for the technologies in your stack.
Filter by severity, product, vendor, date, CWE type, and exploitation status.
Actively exploited vulnerabilities from the CISA Known Exploited Vulnerabilities catalog.
Most recently added CVEs to our database
The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within…
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert…
Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to…
The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape…
The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one…
Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This…
Vendors and products with the highest number of reported vulnerabilities
Explore our comprehensive CVE vulnerability database and stay informed about the latest threats.