CVE Vulnerability Database

Search and browse 394,742 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-48142MEDIUM6.3NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or p...
CVE-2026-48117MEDIUM6.8DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an a...
CVE-2026-47103CRITICAL9.8Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to ...
CVE-2026-42530CRITICAL9.2NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the ...
CVE-2026-42055HIGH8.1NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. ...
CVE-2026-40641MEDIUM4.8Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Use of a Broken or Risky Cryptographic Algorithm vuln...
CVE-2026-35162MEDIUM6.5Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg...
CVE-2026-35067HIGH8Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg...
CVE-2026-35066HIGH7.1Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg...
CVE-2026-35065HIGH8.8Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Authentication for Critical Function vulnerabi...
CVE-2026-32804HIGH8.1Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthentic...
CVE-2026-22283HIGH7.5Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion of Functionality from Untrusted Control Sph...
CVE-2026-12528MEDIUM5.4A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Acce...
CVE-2026-11311MEDIUM6.5When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX...
CVE-2026-10850MEDIUM5.4Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when cre...
CVE-2024-47477MEDIUM6.5Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote un...
CVE-2026-9591MEDIUM6.9Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthent...
CVE-2026-55738HIGH8.8A stack-based buffer overflow exists in the raw_to_header function in src/microtar.c in rxi microtar 0.1.0. The function...
CVE-2026-54819CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listd...
CVE-2026-54818HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimsta...
CVE-2026-54817MEDIUM6.5Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recover...
CVE-2026-54816HIGH7.5Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code ...
CVE-2026-54815CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shi...
CVE-2026-54814HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-54813HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force S...