CVEs

Tenable maintains a list of Common Vulnerabilities and Exposures (CVEs) and their affected products. Tenable augments the data to include related Tenable Plugins that detect each vulnerability. 336966 CVEs are indexed from NVD.

Search

Vulnerability Watch ›

  • CVE-2026-20127
    criticalVulnerability of Interest

    This authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controller has reportedly been exploited in the wild. Immediate patching is recommended

  • CVE-2026-25108
    highVulnerability of Interest

    A command injection vulnerability affecting FileZen has been reportedly exploited in the wild. Immediate patching is recommended.

  • CVE-2022-20775
    highVulnerability of Interest

    Exploitation of this vulnerability targeting Cisco SD-WAN devices has been reported. Immediate patching is recommended

  • CVE-2026-20131
    criticalVulnerability Being Monitored

    Max severity vulnerability in Cisco Secure Firewall Management Center (FMC). We're monitoring for further updates including availability of PoCs.

  • CVE-2026-20079
    criticalVulnerability Being Monitored

    Max severity vulnerability in Cisco Secure Firewall Management Center (FMC). We're monitoring for further updates including availability of PoCs.

Newest ›

  • EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass...

  • The Media Library Assistant plugin for WordPress is vulnerable to unauthorized modification of...

  • The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed...

  • IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for...

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...

  • Inclusion of Functionality from Untrusted Control Sphere vulnerability in WP Royal Royal...

  • Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetEngine...

  • Unrestricted Upload of File with Dangerous Type vulnerability in WP Chill Filr filr-protection...

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...

  • Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...

Updated ›

  • The Apocalypse Meow plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, and including, 22.1.0. This is due to a flawed logical operator in the type validation check on line 261 of ajax.php — the condition uses `&&` (AND) instead of `||` (OR), causing the `in_array()` validation to be short-circuited and never evaluated for any non-empty type value. Combined with `stripslashes_deep()` being called on line 101 which removes `wp_magic_quotes()` protection, attacker-controlled single quotes pass through unescaped into the SQL query on line 298. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

  • A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX Endpoint. Executing a manipulation can lead to code injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 109.2 will fix this issue. This patch is called 08937a3c5d672a242d68f53e9fccf8a748820ef3. You should upgrade the affected component. The code maintainer was informed beforehand about the issues. He reacted very fast and highly professional.

  • A vulnerability was detected in jarikomppa soloud up to 20200207. This affects the function SoLoud::Wav::loadwav of the file src/audiosource/wav/soloud_wav.cpp of the component WAV File Parser. Performing a manipulation results in memory corruption. The attack must be initiated from a local position. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

  • A vulnerability was identified in FascinatedBox lily up to 2.3. This issue affects the function patch_line_end of the file src/lily_build_error.c of the component Error Reporting. The manipulation leads to out-of-bounds read. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

  • A vulnerability was determined in Squirrel up to 3.2. This vulnerability affects the function sqstd_rex_newnode in the library sqstdlib/sqstdrex.cpp. Executing a manipulation can lead to null pointer dereference. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

  • A vulnerability was found in Squirrel up to 3.2. This affects the function SQCompiler::Factor/SQCompiler::UnaryOP of the file squirrel/sqcompiler.cpp. Performing a manipulation results in uncontrolled recursion. The attack needs to be approached locally. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

  • A vulnerability has been found in wren-lang wren up to 0.4.0. Affected by this issue is the function getByteCountForArguments of the file src/vm/wren_compiler.c. Such manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

  • A flaw has been found in wren-lang wren up to 0.4.0. Affected by this vulnerability is the function emitOp of the file src/vm/wren_compiler.c. This manipulation causes out-of-bounds read. It is possible to launch the attack on the local host. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

  • Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib. Compress::Raw::Zlib includes a copy of the zlib library. Compress::Raw::Zlib version 2.220 includes zlib 1.3.2, which addresses findings fron the 7ASecurity audit of zlib. The includes fixs for CVE-2026-27171.

  • UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library. UnQLite for Perl embeds the UnQLite library. Version 0.06 and earlier of the Perl module uses a version of the library from 2014 that may be vulnerable to a heap-based overflow.