CVE Vulnerability Database

Search and browse 394,603 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-10561CRITICAL10IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with...
CVE-2025-66389HIGH7.5GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler...
CVE-2025-33128MEDIUM5.4IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerab...
CVE-2025-2669MEDIUM6.5IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a pri...
CVE-2024-54178MEDIUM6.5IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authen...
CVE-2026-56422CRITICAL9.4Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (i...
CVE-2026-11373CRITICAL9.1Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for th...
CVE-2026-12863MEDIUM5.1An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using...
CVE-2026-12862MEDIUM5.1Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be...
CVE-2026-12581HIGH7.7EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a s...
CVE-2026-12580MEDIUM5.4EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attack...
CVE-2025-4994HIGH8.7The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authenticatio...
CVE-2023-45796HIGH8.1A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to an...
CVE-2023-45795HIGH7.8A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a local unauthenticat...
CVE-2026-54665MEDIUM5.3Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an...
CVE-2026-44914HIGH7.2Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension componen...
CVE-2026-44913HIGH7.2Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2....
CVE-2026-44911MEDIUM6.3Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clie...
CVE-2025-66336HIGH8.1Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name...
CVE-2025-62198MEDIUM5.4An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier. Users are recommend...
CVE-2026-8157HIGH8.8The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new u...
CVE-2026-7859MEDIUM5.3The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX action...
CVE-2026-6858HIGH7.1The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthen...
CVE-2026-4259HIGH7.1The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outp...
CVE-2026-4110MEDIUM6.1The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outp...