CVE Vulnerability Database

Search and browse 390,072 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-58384HIGH7.8A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation...
CVE-2026-13199MEDIUM5.1EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. This resul...
CVE-2026-8377HIGH8.2Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Colle...
CVE-2026-8309MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information...
CVE-2026-8306MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information...
CVE-2026-7380MEDIUM6.1Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Techno...
CVE-2026-5799HIGH7.5Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime a...
CVE-2026-5730HIGH7.5Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime a...
CVE-2026-58315MEDIUM5.1Cross-site request forgery vulnerability exists in SEIKO EPSON Web Config. If a user views a malicious page while logged...
CVE-2026-57871HIGH7.1Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overw...
CVE-2026-57870MEDIUM5.3Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document template...
CVE-2026-57869HIGH7.1Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstat...
CVE-2026-57868HIGH7.1MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. This issue affects M...
CVE-2026-57867HIGH8.8MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit a...
CVE-2026-4375CRITICAL9The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to...
CVE-2026-14345CRITICAL9.8The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Re...
CVE-2026-12375CRITICAL9.8The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny...
CVE-2026-12277HIGH8.7The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input bef...
CVE-2026-10834MEDIUM4.6The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile ima...
CVE-2026-42201LOW3.3Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34158HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-27844LOW2.7Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated...
CVE-2026-27790LOW2.7Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by ...
CVE-2026-26053MEDIUM5.3An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator ...
CVE-2026-42200HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....