CVE Vulnerability Database

Search and browse 390,029 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-58306MEDIUM6.1Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Es...
CVE-2026-58305MEDIUM6.1Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Point...
CVE-2026-58304MEDIUM6.1Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This iss...
CVE-2026-58303MEDIUM6.1Stack-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects E...
CVE-2026-56291CRITICAL9.8Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension B...
CVE-2026-56289MEDIUM5.5GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff...
CVE-2026-56288MEDIUM5.5GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Impro...
CVE-2026-50644HIGH8.6SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all right...
CVE-2026-4298MEDIUM4.3The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and includ...
CVE-2026-4275HIGH8.8The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request F...
CVE-2026-14372HIGH7.1The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is v...
CVE-2026-13441HIGH7.2The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2026-12590MEDIUM5.9Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an i...
CVE-2026-12428MEDIUM6.5The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ...
CVE-2026-5955CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software an...
CVE-2026-5793MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software an...
CVE-2026-56460MEDIUM6.5HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API respons...
CVE-2026-56459MEDIUM5.5HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure.  The application stores potentially s...
CVE-2026-56458HIGH7.5HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged action...
CVE-2026-2342CRITICAL9.3Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Inform...
CVE-2026-1989HIGH7.5Authorization bypass through User-Controlled key vulnerability in PAVO Financial Technology Solutions Inc. PAVO Pay allo...
CVE-2026-1365MEDIUM6.5Insertion of sensitive information into sent data vulnerability in Sayax Energy Technologies Inc. OSOS allows Authentica...
CVE-2026-15158CRITICAL9.8The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, ...
CVE-2026-12433MEDIUM4.3The Hydra Booking – Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Obje...
CVE-2026-8996MEDIUM6.5The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve...