CVE Vulnerability Database

Search and browse 394,518 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-4610MEDIUM6.4The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2026-44089CRITICAL9.4Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. Thi...
CVE-2026-10857MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in AKIN Software Comp...
CVE-2026-10711HIGH8.8Missing authentication for critical function vulnerability in AKIN Software Computer Import Export Industry and Trade Lt...
CVE-2025-71376HIGH8.1picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.autocomplete.AutoComplete.fetch_completion...
CVE-2025-71370HIGH8.1picklescan before 0.0.28 fails to detect malicious torch.jit.unsupported_tensor_ops.execWrapper function calls embedded ...
CVE-2025-71365HIGH8.1picklescan before 0.0.33 fails to detect malicious pickle files that invoke numpy.f2py.crackfortran.myeval function thro...
CVE-2025-71341HIGH8.1picklescan before 0.0.29 fails to detect the profile.Profile.runctx function when analyzing pickle files, allowing attac...
CVE-2025-71337HIGH8.7Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authen...
CVE-2023-54365HIGH8.7Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inheri...
CVE-2026-4983MEDIUM5.4Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content...
CVE-2026-11374CRITICAL9In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated...
CVE-2026-9733CRITICAL9.1Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no...
CVE-2026-10521HIGH8.6An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, ...
CVE-2026-8379HIGH7.5The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file dow...
CVE-2026-8378MEDIUM5.4The Frontend File Manager Plugin WordPress plugin through 23.6 does not sanitise nor escape a filename submitted to the ...
CVE-2026-8172HIGH7.1The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it...
CVE-2026-8163HIGH8.8The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using t...
CVE-2026-7842MEDIUM6.8The Infility Global Infility Global WordPress plugin before 2.15.20 for WordPress does not sanitize or validate the orde...
CVE-2026-12866CRITICAL9.8All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execu...
CVE-2026-55655MEDIUM6.1A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding ...
CVE-2026-55654LOW3.7A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic...
CVE-2026-55653MEDIUM6.5A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group ...
CVE-2026-11833HIGH8.2Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing t...
CVE-2026-10658HIGH7.1bt_iso_recv() in subsys/bluetooth/host/iso.c pulled the ISO SDU header (4 bytes) or, when the timestamp flag is set, the...