CVE Vulnerability Database

Search and browse 392,387 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-24815HIGH7.8Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Succ...
CVE-2026-45822MEDIUM6.6decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' produci...
CVE-2026-12578HIGH8.4The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitr...
CVE-2026-9576MEDIUM4.9The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting a...
CVE-2026-56809MEDIUM5.1Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cr...
CVE-2026-56808HIGH8.6DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead to arb...
CVE-2026-56137HIGH8.4RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads ...
CVE-2026-14164HIGH7.5A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive,...
CVE-2026-12819CRITICAL9.3Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access contro...
CVE-2026-12818CRITICAL9.3Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-...
CVE-2026-12240HIGH8The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat...
CVE-2026-11590HIGH8.6The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sanitize user-supplied array keys b...
CVE-2026-11589HIGH8.8The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not properly validate uploaded files, a...
CVE-2026-11581MEDIUM5.9The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's ca...
CVE-2026-8944MEDIUM4.3The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in v...
CVE-2026-12560MEDIUM4.4The Editorial Rating – Product Review & Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2026-12349MEDIUM5.3The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in ...
CVE-2026-12073CRITICAL9.8The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via a...
CVE-2026-11367MEDIUM6.5The PixMagix – WordPress Image Editor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, a...
CVE-2026-14160MEDIUM5.9Time-of-check time-of-use (TOCTOU) race condition vulnerability in Samsung Open Source Escargot allows Leveraging Race C...
CVE-2026-12114MEDIUM4.4The Team Members – Multi Language Supported Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2026-58302HIGH8.4rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads s...
CVE-2026-12243Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-8023HIGH7.5Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, ava...
CVE-2026-7656MEDIUM6.8The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) use...