CVE Vulnerability Database

Search and browse 394,712 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-51843CRITICAL9.8Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the w...
CVE-2026-49260HIGH8.2PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/...
CVE-2026-3196MEDIUM5.5An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious g...
CVE-2026-3195HIGH7.4A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` f...
CVE-2019-25748HIGH8.2Joomla JHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute ...
CVE-2017-20282HIGH8.2Joomla! Component jCart for OpenCart 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers t...
CVE-2017-20281HIGH8.2Joomla! Component Extra Search 2.2.8 contains an SQL injection vulnerability that allows unauthenticated attackers to ma...
CVE-2017-20280HIGH8.2Joomla Component Myportfolio 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to mani...
CVE-2017-20279HIGH8.2Joomla Payage 2.05 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database ...
CVE-2017-20278HIGH8.2Joomla Component JoomRecipe 1.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to manip...
CVE-2017-20277HIGH8.2Joomla JoomRecipe 1.0.4 component contains a blind SQL injection vulnerability in the search_author parameter on the sea...
CVE-2017-20276HIGH8.2Joomla! Component SIMGenealogy 2.1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to ma...
CVE-2017-20275HIGH8.2Joomla! Component PHP-Bridge 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to exec...
CVE-2017-20274HIGH8.2Joomla LMS King Professional 3.2.4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to ma...
CVE-2017-20273HIGH8.2Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated attacke...
CVE-2017-20272HIGH8.2Joomla Ultimate Property Listing 1.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to ...
CVE-2017-20271HIGH8.2Joomla StreetGuessr Game 1.1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute ...
CVE-2017-20270HIGH8.2Joomla! Component Twitch Tv 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute...
CVE-2017-20269HIGH8.2Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inj...
CVE-2017-20268HIGH8.2Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers ...
CVE-2026-12622MEDIUM5.4The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission. This issu...
CVE-2026-12621MEDIUM5.4Improper neutralization of input during web page generation XSS vulnerability in the GridTime 3000 (password reset form...
CVE-2026-12620MEDIUM6.5The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects G...
CVE-2026-12619MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip G...
CVE-2017-20267HIGH8.2Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers t...