CVE Vulnerability Database

Search and browse 394,735 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-11775MEDIUM4.3The User Admin Simplifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2026-52866HIGH7.1An attacker within BLE communication range can monopolize the device's only available BLE connection slot, preventing l...
CVE-2026-50034HIGH7.1An attacker within BLE communication range can passively intercept wireless traffic and obtain sensitive health-related...
CVE-2026-40624CRITICAL9.8Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated att...
CVE-2026-12050HIGH8.8SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-sup...
CVE-2026-12049MEDIUM6.1Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoints honoured the user...
CVE-2026-12048MEDIUM5.4Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL ...
CVE-2026-12047MEDIUM5.4HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoi...
CVE-2026-12046CRITICAL9.5Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqledit...
CVE-2026-12045HIGH8.8Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that th...
CVE-2026-12044HIGH8.8SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-su...
CVE-2026-6716Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-56078HIGH8.8PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs w...
CVE-2026-56077HIGH7.1PraisonAI before 1.5.115 contains an information disclosure vulnerability in the MultiAgentLedger component that allows ...
CVE-2026-56076HIGH8.6PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote a...
CVE-2026-56075HIGH8.8PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode appro...
CVE-2026-56074MEDIUM6.8PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequ...
CVE-2026-10746Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-8668LOW2.3A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues.  Q...
CVE-2026-8100HIGH8.6Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints...
CVE-2026-54130HIGH7.5Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information ove...
CVE-2026-54017HIGH7.7Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the t...
CVE-2026-49205MEDIUM6.5phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryC...
CVE-2026-47647CRITICAL9.9Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
CVE-2026-47633HIGH7.5Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthor...