CVE Vulnerability Database

Search and browse 394,557 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-11374CRITICAL9In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated...
CVE-2026-9733CRITICAL9.1Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no...
CVE-2026-10521HIGH8.6An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, ...
CVE-2026-8379HIGH7.5The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file dow...
CVE-2026-8378MEDIUM5.4The Frontend File Manager Plugin WordPress plugin through 23.6 does not sanitise nor escape a filename submitted to the ...
CVE-2026-8172HIGH7.1The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it...
CVE-2026-8163HIGH8.8The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using t...
CVE-2026-7842MEDIUM6.8The Infility Global Infility Global WordPress plugin before 2.15.20 for WordPress does not sanitize or validate the orde...
CVE-2026-12866CRITICAL9.8All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execu...
CVE-2026-55655MEDIUM6.1A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding ...
CVE-2026-55654LOW3.7A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic...
CVE-2026-55653MEDIUM6.5A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group ...
CVE-2026-11833HIGH8.2Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing t...
CVE-2026-10658HIGH7.1bt_iso_recv() in subsys/bluetooth/host/iso.c pulled the ISO SDU header (4 bytes) or, when the timestamp flag is set, the...
CVE-2026-10651MEDIUM6.5bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-...
CVE-2026-10645MEDIUM5.5The Zephyr ext2 filesystem driver (subsys/fs/ext2) trusted the on-disk directory entry fields de_rec_len and de_name_len...
CVE-2026-54236MEDIUM5.3vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, the fix for CVE-2026-22778...
CVE-2026-54235MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, ll temperature validation ...
CVE-2026-54233MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, vLLM's /v1/audio/transcrip...
CVE-2026-54232HIGH8.8vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulner...
CVE-2026-53923HIGH7.5vLLM is an inference and serving engine for large language models (LLMs). From 0.5.5 until 0.23.1rc0, integer truncation...
CVE-2026-48746CRITICAL9.1vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in AS...
CVE-2026-47155MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning contr...
CVE-2026-41523HIGH7.5vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security chec...
CVE-2026-56698MEDIUM6.1Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 fail to validate script-capable URLs in the navigateTo open optio...