CVE Vulnerability Database

Search and browse 389,982 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-22098CRITICAL9.2Various sensitive information such as passwords and charging card UIDs are written to log files.
CVE-2026-22097CRITICAL9.3The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the...
CVE-2026-22096CRITICAL9.3The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such a...
CVE-2026-22095CRITICAL9.3The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.
CVE-2026-22093CRITICAL9.5The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided b...
CVE-2026-15557HIGH7.3A weakness has been identified in waooAI waoowaoo up to 0.4.1. Affected by this vulnerability is the function getInterna...
CVE-2026-15548HIGH8.8A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. This vulnerability affects the function sub...
CVE-2026-14846MEDIUM4.5In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by i...
CVE-2026-13014CRITICAL9.2A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute...
CVE-2026-9708MEDIUM4.9Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming w...
CVE-2026-9597MEDIUM5.4Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before crea...
CVE-2026-9571MEDIUM6.5Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon...
CVE-2026-6850MEDIUM6.5Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of m...
CVE-2026-62143HIGH8.3A Server-Side Request Forgery (SSRF) protection bypass existed in the html_to_markdown expansion module of misp-modules....
CVE-2026-15574HIGH7.5A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorizat...
CVE-2026-15547MEDIUM6.3A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048 of the component CI...
CVE-2026-15546MEDIUM6.3A security flaw has been discovered in Shibby Tomato up to 1.28.0000. Affected by this issue is the function sub_2D568 o...
CVE-2026-15545HIGH8.8A vulnerability was identified in Shibby Tomato up to 1.28.0000. Affected by this vulnerability is the function main of ...
CVE-2026-14453CRITICAL9.6This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that l...
CVE-2026-10106MEDIUM6.5Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced i...
CVE-2026-10103MEDIUM4.3Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared ...
CVE-2026-10085MEDIUM5.4Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained chann...
CVE-2026-57830CRITICAL9.1Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla exten...
CVE-2026-57829MEDIUM6.1Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ul...
CVE-2026-4769CRITICAL9.8Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startu...