CVE Vulnerability Database

Search and browse 395,431 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-5497HIGH7.5vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded f...
CVE-2026-53911MEDIUM6.3Cerebrate before version 1.37 allowed the id primary key field to be supplied through request input during CRUD edit ope...
CVE-2026-11850MEDIUM5An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_lda...
CVE-2025-7064MEDIUM6.6Authentication bypass by primary weakness vulnerability in ABB Freelance. This issue affects Freelance: through 2013, 2...
CVE-2022-44630MEDIUM4.6Cross-Site request forgery (CSRF) vulnerability in YITH YITH WooCommerce Product Slider Carousel allows Cross Site Reque...
CVE-2022-42479MEDIUM5.4Missing Authorization vulnerability in TemplateHouse Soledad allows Accessing Functionality Not Properly Constrained by ...
CVE-2026-53901HIGH8.7Cerebrate before version 1.37 contains a mass-assignment vulnerability in the generic CRUD add path. The add() handler a...
CVE-2024-32110MEDIUM4.3Cross-Site request forgery (CSRF) vulnerability in Magepeople inc. WpEvently allows Cross Site Request Forgery. This is...
CVE-2023-40200MEDIUM5.3Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase Responsive Slider an...
CVE-2023-33999HIGH7.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Lo...
CVE-2026-41856HIGH7.5The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on...
CVE-2026-41700HIGH8.1Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacki...
CVE-2026-41699CRITICAL9.8Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An a...
CVE-2026-41001MEDIUM5.3Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's da...
CVE-2026-41000LOW3.7Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-ti...
CVE-2026-40999HIGH8.6When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections ...
CVE-2026-40998HIGH8.2Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed atta...
CVE-2026-40997MEDIUM5.3Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or dis...
CVE-2026-40996MEDIUM4.8Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for ...
CVE-2026-40995MEDIUM5.4X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped...
CVE-2026-40994HIGH8.2Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation di...
CVE-2026-40992MEDIUM5Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail...
CVE-2026-40987HIGH7.1A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the ...
CVE-2026-40986MEDIUM4.8Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not...
CVE-2026-10795HIGH8.1The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all version...