CVE Vulnerability Database

Search and browse 390,162 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-34100HIGH8.8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELE...
CVE-2026-34099CRITICAL9.8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): S...
CVE-2026-34098MEDIUM4.8Guardian language-system fails to sanitize the id GET parameter before inserting it into HTML source and form action att...
CVE-2026-34097MEDIUM4.8Guardian language-system fails to sanitize the id GET parameter before inserting it into multiple HTML form action attri...
CVE-2026-34096MEDIUM4.8Guardian language-system fails to sanitize the name GET parameter before outputting it into an HTML input value attribut...
CVE-2026-27409MEDIUM5.3Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Contr...
CVE-2026-20244HIGH7.5A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c...
CVE-2026-20243HIGH7.5A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c...
CVE-2026-20217HIGH7.5A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a Do...
CVE-2026-20216HIGH7.5A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cau...
CVE-2026-20215HIGH7.5A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS co...
CVE-2026-20214HIGH7.5A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c...
CVE-2026-20213HIGH7.5A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS co...
CVE-2026-20191HIGH7.5A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a ...
CVE-2026-13211MEDIUM4.3The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption ke...
CVE-2026-12480MEDIUM5.5Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE...
CVE-2026-8857HIGH8.8A vulnerability in Wikimedia Foundation timeline. This vulnerability is associated with program files scripts/EasyTime...
CVE-2026-8480MEDIUM4.3A vulnerability was discovered on Stormshield Network Security 4.3.0  to 4.3.41 (included), 4.4.0 to 4.8.15 (included) ,...
CVE-2026-58127CRITICAL9.8PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registere...
CVE-2026-58126CRITICAL9.8PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to...
CVE-2026-58038MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-58037MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-58036HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne...
CVE-2026-58033MEDIUM6.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne...
CVE-2026-58032MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...