CVE Vulnerability Database

Search and browse 390,162 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-49119HIGH8.7Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that all...
CVE-2026-47262MEDIUM5.5containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vuln...
CVE-2026-41121HIGH7.8Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Before File Access ('Lin...
CVE-2026-38142MEDIUM6.5An unauthenticated command injection vulnerability in the /goform/fast_setting_internet_set endpoint of Tenda AC18 v15.0...
CVE-2026-14358MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun...
CVE-2026-13769MEDIUM6.8Overly permissive file permissions in AWS CLI before 1.44.78 (v1) and 2.34.29 (v2) on Unix-like systems where the umask ...
CVE-2026-13760HIGH7.3OS command injection in the NodejsFunction Docker bundling pipeline (OsCommand helper) in AWS aws-cdk-lib on all platfor...
CVE-2026-5051MEDIUM4.4HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin dire...
CVE-2026-58521CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foun...
CVE-2026-58520MEDIUM6.1URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener E...
CVE-2026-57737MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortco...
CVE-2026-57736HIGH7.4Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. Thi...
CVE-2026-57723HIGH7.4Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal....
CVE-2026-57722MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable ...
CVE-2026-54428HIGH7.5Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 an...
CVE-2026-51946MEDIUM6.5SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.2.26) allows a remote attacker to execute arbitrary...
CVE-2026-49091HIGH8Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forgin...
CVE-2026-49090MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (C...
CVE-2026-46680HIGH7.8containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched...
CVE-2026-58454HIGH7.7JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a remote code execution vulnerability that ...
CVE-2026-58453CRITICAL9.8JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that...
CVE-2026-58452HIGH8.8JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain an OS command injection vulnerability that ...
CVE-2026-57721MEDIUM5.3Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control S...
CVE-2026-57720MEDIUM4.3Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control ...
CVE-2026-57516HIGH8.8Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to a...