CVE Vulnerability Database

Search and browse 390,117 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-12729MEDIUM4.3The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Miss...
CVE-2026-8247HIGH8.8An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local n...
CVE-2026-55726MEDIUM6.9The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious us...
CVE-2026-54477MEDIUM5.4The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks.
CVE-2026-13768CRITICAL10Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub R...
CVE-2026-13728MEDIUM4.4In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved...
CVE-2026-13722HIGH7.2WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore featu...
CVE-2026-13384HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged u...
CVE-2026-13383HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged ...
CVE-2026-13377MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2026-13376MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2026-13375MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2026-13374MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2026-13373MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2026-13371MEDIUM4.9An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending ma...
CVE-2026-13368HIGH8.1WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for th...
CVE-2026-13084HIGH7.5A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create...
CVE-2026-13079HIGH7.8A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attac...
CVE-2026-13054HIGH7.2A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacke...
CVE-2026-13053HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to exe...
CVE-2026-13050HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged ...
CVE-2026-57100HIGH8.8Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to...
CVE-2026-54998HIGH8.8Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
CVE-2026-45499HIGH8.8Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
CVE-2026-41106CRITICAL9.3Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privilege...