CVE Vulnerability Database

Search and browse 390,222 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-34110CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) with...
CVE-2026-34109CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (line 18) without san...
CVE-2026-34108CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanit...
CVE-2026-34107CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) without ...
CVE-2026-34106CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without ...
CVE-2026-34105HIGH8.8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line ...
CVE-2026-34104HIGH8.8Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124)...
CVE-2026-34103HIGH8.8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): ...
CVE-2026-34102HIGH8.8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16...
CVE-2026-34101HIGH8.8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): ...
CVE-2026-34100HIGH8.8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELE...
CVE-2026-34099CRITICAL9.8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): S...
CVE-2026-34098MEDIUM4.8Guardian language-system fails to sanitize the id GET parameter before inserting it into HTML source and form action att...
CVE-2026-34097MEDIUM4.8Guardian language-system fails to sanitize the id GET parameter before inserting it into multiple HTML form action attri...
CVE-2026-34096MEDIUM4.8Guardian language-system fails to sanitize the name GET parameter before outputting it into an HTML input value attribut...
CVE-2026-27409MEDIUM5.3Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Contr...
CVE-2026-20244HIGH7.5A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c...
CVE-2026-20243HIGH7.5A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c...
CVE-2026-20217HIGH7.5A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a Do...
CVE-2026-20216HIGH7.5A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cau...
CVE-2026-20215HIGH7.5A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS co...
CVE-2026-20214HIGH7.5A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c...
CVE-2026-20213HIGH7.5A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS co...
CVE-2026-20191HIGH7.5A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a ...
CVE-2026-13211MEDIUM4.3The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption ke...