CVE Vulnerability Database

Search and browse 394,301 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-57587MEDIUM5.3A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a...
CVE-2026-57536MEDIUM6.3Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a success...
CVE-2026-57535LOW2.1Content injected to PDF rendering contexts could, in many places, include HTML content including <img> tags. If the src ...
CVE-2026-57534LOW2.1Malicious HTML content could be injected into the content of a page in the pretix-pages plugin.
CVE-2026-57533LOW2.1Malicious HTML content could be injected into the page pretix shows when redirection to an untrusted page occurs. Since...
CVE-2026-57532HIGH8.8Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF ...
CVE-2026-57437MEDIUM5.3Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::XPath...
CVE-2026-57436MEDIUM5.3Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::Docum...
CVE-2026-57435HIGH7.5Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri’s CRuby nat...
CVE-2026-57434HIGH7.5Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri contains a ...
CVE-2026-57236HIGH8.2Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, calling Document#enc...
CVE-2026-57235HIGH8.2Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::NodeS...
CVE-2026-57234LOW2.6Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse opti...
CVE-2026-49319MEDIUM6.9Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0 manufactured by ALPS ALPINE CO., L...
CVE-2026-46735HIGH7.8Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Neutralization of Special Ele...
CVE-2026-13314LOW2Malicious HTML content could be injected into the content rendered by the pretix-digital plugin.
CVE-2026-13225MEDIUM5.3Malicious HTML content could be injected into the email address of an order, which pretix showed without sanitization o...
CVE-2026-13223MEDIUM6.3Our payment integration with Computop-based payment methods did not properly validate payment status responses. An atta...
CVE-2026-13222MEDIUM6.3Our payment integration with Oppwa-based payment methods did not properly validate payment status responses. An attacke...
CVE-2026-57619MEDIUM6.5Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.
CVE-2026-57429MEDIUM6.5Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.
CVE-2026-56122HIGH8.7Winstone Servlet Engine through 0.9.10 contains a path traversal vulnerability that allows unauthenticated attackers to ...
CVE-2026-56071HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions.
CVE-2026-56054HIGH7.7Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.
CVE-2026-56053HIGH8.8Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.