CVE Vulnerability Database

Search and browse 394,231 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-57346HIGH7.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy al...
CVE-2026-25707HIGH8.8A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by re...
CVE-2026-13601MEDIUM6.5A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. ...
CVE-2026-13557MEDIUM4.3A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. This vulnerability affects unknown co...
CVE-2026-13556MEDIUM4.3A vulnerability was determined in itsourcecode Online Hotel Management System 1.0. This affects an unknown part of the f...
CVE-2026-13555HIGH7.3A vulnerability was found in itsourcecode Online Hotel Management System 1.0. Affected by this issue is some unknown fun...
CVE-2026-13554MEDIUM4.3A vulnerability has been found in itsourcecode Online Hotel Management System 1.0. Affected by this vulnerability is an ...
CVE-2026-13553HIGH7.3A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /a...
CVE-2026-13552HIGH7.3A vulnerability was detected in itsourcecode Online Hotel Management System 1.0. This impacts an unknown function of the...
CVE-2026-9267MEDIUM6.9Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in ...
CVE-2026-57966MEDIUM4.4A path traversal vulnerability was found in spice-vdagent. This flaw allows a malicious or compromised SPICE host to wri...
CVE-2026-57965MEDIUM5.1A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a sp...
CVE-2026-57676MEDIUM4.3Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Inco...
CVE-2026-22078HIGH7.3Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perfor...
CVE-2026-13595MEDIUM5.3A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, an...
CVE-2026-13551HIGH7.3A security vulnerability has been detected in itsourcecode Baptism Information Management System 1.0. This affects an un...
CVE-2026-13550HIGH7.3A weakness has been identified in itsourcecode Baptism Information Management System 1.0. The impacted element is an unk...
CVE-2026-13549MEDIUM5.4A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function d...
CVE-2026-13548MEDIUM6.3A vulnerability was identified in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the fi...
CVE-2026-13547HIGH7.3A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. This issue affects some unknown pr...
CVE-2026-13546HIGH7.3A vulnerability was found in Feehi CMS up to 2.1.1. This vulnerability affects unknown code of the file /api/articles of...
CVE-2026-13545HIGH8.8A vulnerability has been found in D-Link DCS-935L 1.10.01. This affects the function sub_400E40 of the file setconf.cgi ...
CVE-2026-9676MEDIUM4.3The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of i...
CVE-2026-13544MEDIUM6.3A flaw has been found in Feehi CMS up to 2.1.1. Affected by this issue is some unknown functionality of the file /api/us...
CVE-2026-13543MEDIUM5.6A vulnerability was detected in Documenso up to 2.11.0. Affected by this vulnerability is an unknown functionality of th...