CVE Vulnerability Database

Search and browse 394,408 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-12846CRITICAL10GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48...
CVE-2026-12488MEDIUM6.2A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2.  A specially cr...
CVE-2026-12486CRITICAL9.1Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09...
CVE-2026-12485CRITICAL10GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48...
CVE-2026-3652HIGH7.2The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save...
CVE-2026-11614MEDIUM6.4The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '...
CVE-2026-12681HIGH8.9Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSig...
CVE-2026-54639HIGH8.8Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability starting in...
CVE-2026-7574HIGH8.7Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348.0, v1...
CVE-2026-6458MEDIUM5.1Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authenticat...
CVE-2026-5818HIGH7.2Incorrect check of function return value in Caliptra Core Runtime Firmware (ActivateFirmwareCmd::activate_fw modules) al...
CVE-2026-56785HIGH8.4FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email f...
CVE-2026-54588CRITICAL9.6Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacke...
CVE-2026-48493MEDIUM5.5Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PA...
CVE-2026-47693MEDIUM6.9Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 are vulnerable ...
CVE-2026-12164MEDIUM4.4Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0 may assign incorrect or el...
CVE-2026-12163MEDIUM4.8Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0.1 contain a stored cross-s...
CVE-2026-11972HIGH8.2When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly h...
CVE-2026-54518MEDIUM6.5jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From...
CVE-2026-9073MEDIUM6.2A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitiv...
CVE-2026-56120Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-20...
CVE-2026-54517MEDIUM5.3jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From...
CVE-2026-54516MEDIUM5.3jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From...
CVE-2026-54515MEDIUM5.3jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From...
CVE-2026-54514MEDIUM5.3jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From...