CVE Vulnerability Database

Search and browse 390,029 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-54801HIGH8.6A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst...
CVE-2026-54800MEDIUM6.3A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst...
CVE-2026-54799HIGH8.4A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst...
CVE-2026-54798HIGH7.1A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst...
CVE-2026-60095MEDIUM6.9Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buffer overflow vulnerability in the ModuleHandShake func...
CVE-2026-60094MEDIUM6.9Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated ...
CVE-2026-4256HIGH8.2Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology ...
CVE-2026-15186MEDIUM6.3A vulnerability was identified in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /returnApply...
CVE-2026-15185LOW3.3A vulnerability was determined in GPAC 26.03-DEV. This affects the function vobsub_read_idx of the file /src/media_tools...
CVE-2026-14261CRITICAL9.1A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation ...
CVE-2026-12879MEDIUM5.9An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google...
CVE-2026-12593HIGH8.7The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to en...
CVE-2026-12116CRITICAL9.8A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings,...
CVE-2026-15184LOW3.3A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_next_entity of the file...
CVE-2026-9253HIGH7.2The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2026-15182MEDIUM5.3A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affected element is the function dwg_bmp of the file sr...
CVE-2026-9240MEDIUM4.3The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modif...
CVE-2026-9237MEDIUM4.3The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization byp...
CVE-2026-9235MEDIUM4.3The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of ...
CVE-2026-9028MEDIUM5.3The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up ...
CVE-2026-9027MEDIUM5.3The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification...
CVE-2026-9021MEDIUM5.3The Easy Invoice plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.19. T...
CVE-2026-59692HIGH7.5A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificat...
CVE-2026-59691HIGH7.1A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/V...
CVE-2026-58307MEDIUM6.1Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Dat...