CVE Vulnerability Database

Search and browse 394,249 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-5757HIGH7.5Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to ...
CVE-2026-47214HIGH7.1Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos...
CVE-2026-45195HIGH7.8Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memor...
CVE-2026-44018HIGH7.1Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos...
CVE-2026-21734HIGH7.7A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-...
CVE-2026-12411CRITICAL9.6Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, r...
CVE-2026-0828HIGH7.5Kernel driver ProcessMonitorDriver.sys in Safetica's endpoint client x64 , versions 10.5.75.0 and 11.11.4.0, allows unpr...
CVE-2026-0685CRITICAL9.8Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows...
CVE-2025-11919CRITICAL9.6The default JVM can access files and directories under `/tmp/` including the `$TemporaryDirectory` of other users on the...
CVE-2023-20572MEDIUM5.6An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against th...
CVE-2023-20540LOW1.8An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against th...
CVE-2026-9699MEDIUM6.8Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before ...
CVE-2026-57667HIGH8.5Sales Representative SQL Injection in Groundhogg <= 4.5 versions.
CVE-2026-57665MEDIUM5.3Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions.
CVE-2026-57664MEDIUM4.3Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder <= 1.1.6 versions.
CVE-2026-57663HIGH8.5Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions.
CVE-2026-57662HIGH8.5Contributor SQL Injection in Contest Gallery <= 30.0.0 versions.
CVE-2026-57661MEDIUM5.4Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions.
CVE-2026-57660MEDIUM5.3Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.
CVE-2026-57659HIGH8.8Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0.7.2 versions.
CVE-2026-57658CRITICAL9.1Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions.
CVE-2026-57657MEDIUM4.3Unauthenticated Cross Site Request Forgery (CSRF) in Gmail SMTP <= 1.2.3.19 versions.
CVE-2026-57656MEDIUM5.9Author Cross Site Scripting (XSS) in Hester Core <= 1.1.8 versions.
CVE-2026-57655HIGH8.2Unauthenticated Cross Site Request Forgery (CSRF) in Child Theme Wizard <= 1.4 versions.
CVE-2026-57654MEDIUM6.5Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.