CVE Vulnerability Database

Search and browse 395,821 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-24719HIGH7.2A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack...
CVE-2026-24717MEDIUM6.5A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker ...
CVE-2026-24716HIGH7.2A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2026-22899MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user a...
CVE-2026-22893HIGH7.2A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack...
CVE-2025-66281HIGH7.2A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote ...
CVE-2025-66280HIGH7.2An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a...
CVE-2025-66279HIGH7.2A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack...
CVE-2025-66273HIGH7.2A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack...
CVE-2025-62851MEDIUM4.4A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator ac...
CVE-2025-62850HIGH7.2A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-66276CRITICAL9.8QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250...
CVE-2025-59382LOW1.2QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:
CVE-2025-58468HIGH8.8A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers ...
CVE-2026-46532MEDIUM4.6ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0...
CVE-2026-45542HIGH7.1ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0...
CVE-2026-45541HIGH7.5ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0...
CVE-2026-45329MEDIUM6.5ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secu...
CVE-2026-45328HIGH8.8ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee componen...
CVE-2026-45160MEDIUM6.5ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0...
CVE-2026-46546MEDIUM5.4Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version ...
CVE-2026-44634HIGH8.7SimpleBLE is a cross-platform library and bindings for Bluetooth Low Energy (BLE). Prior to version 0.14.0, there are mu...
CVE-2026-53675MEDIUM5.3BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any aut...
CVE-2026-53674HIGH7.1BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when user...
CVE-2026-53673HIGH8.6BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authen...