CVE Vulnerability Database

Search and browse 392,294 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-46680HIGH7.8containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched...
CVE-2026-58454HIGH7.7JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a remote code execution vulnerability that ...
CVE-2026-58453CRITICAL9.8JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that...
CVE-2026-58452HIGH8.8JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain an OS command injection vulnerability that ...
CVE-2026-57721MEDIUM5.3Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control S...
CVE-2026-57720MEDIUM4.3Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control ...
CVE-2026-57516HIGH8.8Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to a...
CVE-2026-56152MEDIUM5.3Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality ...
CVE-2026-56151MEDIUM6.5Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An...
CVE-2026-56150HIGH7.5Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Exces...
CVE-2026-56149MEDIUM4.9Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce...
CVE-2026-56148MEDIUM6.5Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). ...
CVE-2026-54399HIGH7.5Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and ...
CVE-2026-49088MEDIUM4.4Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the option...
CVE-2026-49087MEDIUM6.5Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A...
CVE-2026-34117CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in text_to_subtitles.php (line 19) ...
CVE-2026-34116CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.php (line 15) without...
CVE-2026-34115CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe_amazon.php (line 15) ...
CVE-2026-34114CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate_text.php (line 18) wit...
CVE-2026-34113CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech_text.php (line 18) withou...
CVE-2026-34112CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac.php (line 18) without ...
CVE-2026-34111CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac_text.php (line 18) wit...
CVE-2026-34110CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) with...
CVE-2026-34109CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (line 18) without san...
CVE-2026-34108CRITICAL9.8Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanit...