CVE Vulnerability Database

Search and browse 395,834 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-59382LOW1.2QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:
CVE-2025-58468HIGH8.8A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers ...
CVE-2026-46532MEDIUM4.6ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0...
CVE-2026-45542HIGH7.1ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0...
CVE-2026-45541HIGH7.5ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0...
CVE-2026-45329MEDIUM6.5ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secu...
CVE-2026-45328HIGH8.8ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee componen...
CVE-2026-45160MEDIUM6.5ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0...
CVE-2026-46546MEDIUM5.4Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version ...
CVE-2026-44634HIGH8.7SimpleBLE is a cross-platform library and bindings for Bluetooth Low Energy (BLE). Prior to version 0.14.0, there are mu...
CVE-2026-53675MEDIUM5.3BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any aut...
CVE-2026-53674HIGH7.1BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when user...
CVE-2026-53673HIGH8.6BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authen...
CVE-2026-47838HIGH8.1SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead ...
CVE-2026-46545HIGH7.5Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46543MEDIUM5.3Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46542MEDIUM4.3Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46541HIGH7.5Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46540MEDIUM6.5Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46539MEDIUM5.9Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46518HIGH8.7OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...
CVE-2026-46517HIGH7.8LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardc...
CVE-2026-46491HIGH8.6SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to versio...
CVE-2026-46432HIGH7.8LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDep...
CVE-2026-46411MEDIUM6.5FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.2, authorized clients have t...