CVE Vulnerability Database

Search and browse 395,319 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-6277MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 13.9 before 18.10.8, 18.11 before 18.11.5, and 1...
CVE-2026-6269MEDIUM5.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, a...
CVE-2026-53912MEDIUM5.1Cerebrate before version 1.37 exposed credential material from self-registration requests. The self-registration workflo...
CVE-2026-53423MEDIUM5.9Allocation of Resources Without Limits or Throttling vulnerability in membraneframework membrane_mp4_plugin allows unaut...
CVE-2026-4764CRITICAL9.4A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform all...
CVE-2026-3553LOW3.1GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, an...
CVE-2026-1500MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, a...
CVE-2026-10733MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, an...
CVE-2026-10087HIGH8.7GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 1...
CVE-2023-32959MEDIUM4.3Missing Authorization vulnerability in Sparkle WP MetroStore metrostore allows Exploiting Incorrectly Configured Access ...
CVE-2023-25969MEDIUM5.4Missing Authorization vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder allows Exploiting Incorrectl...
CVE-2022-47150MEDIUM4.3Cross-Site request forgery (CSRF) vulnerability in weDevs WooCommerce Conversion Tracking allows Cross Site Request Forg...
CVE-2022-45813MEDIUM5.4Missing Authorization vulnerability in BeRocket Advanced AJAX Product Filters allows Exploiting Incorrectly Configured A...
CVE-2026-5497HIGH7.5vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded f...
CVE-2026-53911MEDIUM6.3Cerebrate before version 1.37 allowed the id primary key field to be supplied through request input during CRUD edit ope...
CVE-2026-11850MEDIUM5An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_lda...
CVE-2025-7064MEDIUM6.6Authentication bypass by primary weakness vulnerability in ABB Freelance. This issue affects Freelance: through 2013, 2...
CVE-2022-44630MEDIUM4.6Cross-Site request forgery (CSRF) vulnerability in YITH YITH WooCommerce Product Slider Carousel allows Cross Site Reque...
CVE-2022-42479MEDIUM5.4Missing Authorization vulnerability in TemplateHouse Soledad allows Accessing Functionality Not Properly Constrained by ...
CVE-2026-53901HIGH8.7Cerebrate before version 1.37 contains a mass-assignment vulnerability in the generic CRUD add path. The add() handler a...
CVE-2024-32110MEDIUM4.3Cross-Site request forgery (CSRF) vulnerability in Magepeople inc. WpEvently allows Cross Site Request Forgery. This is...
CVE-2023-40200MEDIUM5.3Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase Responsive Slider an...
CVE-2023-33999HIGH7.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Lo...
CVE-2026-41856HIGH7.5The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on...
CVE-2026-41700HIGH8.1Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacki...