CVE Vulnerability Database

Search and browse 394,231 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-54369HIGH7.1acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(...
CVE-2026-40524HIGH8.1FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the get_gl_transactions() function where the fil...
CVE-2026-40523HIGH8.1FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Audit Trail report handler that allows authe...
CVE-2026-40522HIGH7.1FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows au...
CVE-2026-40521HIGH8.8FrontAccounting before 2.4.20 contains a path traversal vulnerability in the attachment upload handler that allows authe...
CVE-2026-13676HIGH7.5fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The I...
CVE-2026-13570LOW3.5A vulnerability was detected in SourceCodester Inventory Management System 1.0. Impacted is an unknown function of the f...
CVE-2026-13569MEDIUM4.7A security vulnerability has been detected in weng-xianhu EyouCMS up to 1.7.1. This issue affects some unknown processin...
CVE-2026-13568HIGH7.3A weakness has been identified in SourceCodester Inventory Management System 1.0. This vulnerability affects unknown cod...
CVE-2026-13567MEDIUM4.3A security flaw has been discovered in code-projects Online Music Site 1.0. This affects an unknown part of the file /Fr...
CVE-2026-13566HIGH7.3A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u...
CVE-2026-13565HIGH7.3A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerabi...
CVE-2026-13165HIGH8.6SzafirHost verifies the downloaded native library archive with one JarFile parser (reading the Central Directory) but ex...
CVE-2026-12856HIGH8.8A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extensio...
CVE-2026-12616MEDIUM6.9The /v1/upload/sbom endpoint extracts the iss claim from the attacker-supplied JWT with signature verification disabled,...
CVE-2026-11979HIGH7.8libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. T...
CVE-2026-41992HIGH7.5GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shar...
CVE-2026-41991MEDIUM4.7GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp util...
CVE-2026-13564HIGH8.8A vulnerability was found in Edimax EW-7478APC 1.04. Affected is the function formPPPoESetup of the file /goform/formPPP...
CVE-2026-13563HIGH8.8A vulnerability has been found in Edimax EW-7478APC 1.04. This impacts the function formL2TPSetup of the file /goform/fo...
CVE-2026-13562HIGH8.8A flaw has been found in Edimax EW-7478APC 1.04. This affects the function formiNICSiteSurvey of the file /goform/formiN...
CVE-2026-13561MEDIUM6.3A vulnerability was detected in Edimax EW-7478APC 1.04. The impacted element is the function formiNICbasic of the file /...
CVE-2026-13560MEDIUM6.3A security vulnerability has been detected in Edimax EW-7478APC 1.04. The affected element is the function formAccept of...
CVE-2026-13559HIGH7.3A weakness has been identified in code-projects Real State Services 1.0. Impacted is an unknown function of the file /si...
CVE-2026-13558LOW3.5A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown proces...