CVE Vulnerability Database

Search and browse 395,250 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-11967HIGH8.5MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a ma...
CVE-2026-11879HIGH8.5MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading mali...
CVE-2017-20240MEDIUM5.9Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq...
CVE-2026-49347MEDIUM5.3Quest Bot is an opensource Discord Bot. Prior to version 1.1.8, any user who can access the ticket panel can repeatedly ...
CVE-2026-48485LOW2.1Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the latest release suppresses mentions when creating, un...
CVE-2026-47197HIGH7.2Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, a moderator with the relevant Discord permission bit can...
CVE-2026-47196HIGH8.4Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the automod add command trims user input but does not re...
CVE-2026-47195HIGH7.1Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the purge and slowmode commands check only guild-level p...
CVE-2026-9266HIGH7A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial...
CVE-2026-11849CRITICAL9.8The  iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing una...
CVE-2026-11848HIGH7.9The iRM-IEI Remote Management developed by IEI Integration Corp has a Missing Authentication vulnerability, allowing una...
CVE-2026-50645HIGH7.5There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache...
CVE-2026-50634MEDIUM6.5A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was...
CVE-2026-50633HIGH8.1A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code exec...
CVE-2026-50632HIGH8.1A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache...
CVE-2026-50631HIGH7.4A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-u...
CVE-2026-50630MEDIUM6.5A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate res...
CVE-2026-50629MEDIUM5.3The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages wi...
CVE-2026-50628CRITICAL9.8A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly all...
CVE-2026-50627CRITICAL9.1The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tok...
CVE-2026-50623MEDIUM4.8An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 't...
CVE-2026-49875CRITICAL9.8Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary...
CVE-2026-48914MEDIUM6.7A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of...
CVE-2026-11847MEDIUM5.3The  iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Path Traversal vulnerability, allowi...
CVE-2026-11846HIGH8.1The  iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerabilit...