CVE Vulnerability Database

Search and browse 389,978 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-61498CRITICAL9.8Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php en...
CVE-2026-60121CRITICAL9.8Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint...
CVE-2026-40553HIGH7.5Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue...
CVE-2026-40469CRITICAL9.1Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could b...
CVE-2026-40468CRITICAL9.1Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaust...
CVE-2026-40467HIGH7.5Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may ...
CVE-2026-15584HIGH7.5A privilege escalation vulnerability was found in the incluster-checks tool for OpenShift. The tool creates privileged d...
CVE-2026-15559MEDIUM6.3A vulnerability was detected in CodeAstro Simple Online Leave Management System 1.0. This affects an unknown part of the...
CVE-2026-62147MEDIUM6.5The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API respons...
CVE-2026-15558MEDIUM6.3A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. Affected by this issu...
CVE-2026-12257CRITICAL9.3Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. The flaw is located...
CVE-2026-9824MEDIUM4.3Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels per...
CVE-2026-9820LOW3.8Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams end...
CVE-2026-6541MEDIUM4.3Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration change...
CVE-2026-4765NONE0Self Cross-Site Scripting (Self-XSS) vulnerability in the RD Station Conversas chat feature. The vulnerability lies in t...
CVE-2026-14934CRITICAL9.4A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Co...
CVE-2026-61985MEDIUM5.3Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectl...
CVE-2026-61983MEDIUM5.3Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Acc...
CVE-2026-61977MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-sea...
CVE-2026-61976MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Ele...
CVE-2026-61975MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-re...
CVE-2026-61971LOW2.7Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-pictu...
CVE-2026-61970MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in Themeisle Auto Featured Image (Auto Post Thumbnail) auto-post-thumbn...
CVE-2026-61968MEDIUM5.4Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control ...
CVE-2026-61958MEDIUM5.4Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows...