CVE Vulnerability Database

Search and browse 394,846 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-50869CRITICAL9.8An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplyi...
CVE-2026-49954HIGH8.6Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authenticated a...
CVE-2026-49953MEDIUM6.9Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows unauthenticated remo...
CVE-2026-49952CRITICAL9.3Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthentica...
CVE-2026-48114CRITICAL9.8Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and ab...
CVE-2026-47835HIGH7.5In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearc...
CVE-2026-45390CRITICAL9.1In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working dire...
CVE-2026-45389HIGH7.4In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client ...
CVE-2026-45388CRITICAL9.1In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server,...
CVE-2026-41708HIGH7.5In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service ...
CVE-2026-39197MEDIUM6.5An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Serv...
CVE-2026-39196CRITICAL9.8Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in th...
CVE-2026-39118HIGH8.4An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client valid...
CVE-2026-39007HIGH7.5An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitive information via th...
CVE-2026-39006CRITICAL9.8An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component...
CVE-2026-38812CRITICAL9.8RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generatio...
CVE-2026-38329CRITICAL9.8Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoi...
CVE-2026-38065CRITICAL9.8Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ...
CVE-2026-38064CRITICAL9.8Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNu...
CVE-2026-38063CRITICAL9.8Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via...
CVE-2026-38062CRITICAL9.8Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the rat...
CVE-2026-38061CRITICAL9.8Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volum...
CVE-2026-38060CRITICAL9.8Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin p...
CVE-2026-37216MEDIUM6.1Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add.
CVE-2026-36933MEDIUM6.8An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code vi...