CVE Vulnerability Database

Search and browse 395,972 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-47911HIGH7.8Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds write vulnerability that...
CVE-2026-34416MEDIUM6.1OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbit...
CVE-2026-25557MEDIUM5.4Evoluted PHP Directory Listing Script through 4.0.5 contains a reflected cross-site scripting vulnerability in index.php...
CVE-2026-11799HIGH7.5UXSS in Focus for iOS / Klar Webkit navigation. This vulnerability was fixed in Focus for iOS 151.3.1 and Klar for iOS 1...
CVE-2025-71319HIGH8.7image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block th...
CVE-2026-6445HIGH8.7A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information...
CVE-2026-6444HIGH8.6A flaw exists in the FlashArray Purity management interface where an authenticated low-privileged user may, under specif...
CVE-2026-48306HIGH7.8Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2026-48305HIGH7.8Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2026-47910MEDIUM6.3Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Authorization vulnerability that could lead t...
CVE-2026-47909MEDIUM6.3Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Input Validation vulnerability that could lead...
CVE-2026-47908HIGH7.8Dreamweaver Desktop versions 21.7 and earlier are affected by an Access of Uninitialized Pointer vulnerability that coul...
CVE-2026-47907HIGH8.6Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could result...
CVE-2026-47906HIGH8.6Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerabi...
CVE-2026-47106MEDIUM5.4Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a stored cross-site scripting vulnerabili...
CVE-2026-34710HIGH7.8Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2026-34709HIGH7.8Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2026-32856MEDIUM6.1Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a reflected cross-site scripting vulnerab...
CVE-2026-11824HIGH8.5SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that all...
CVE-2026-11822HIGH8.5SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attack...
CVE-2026-8863HIGH7.8Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative pri...
CVE-2026-40639MEDIUM5.7Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical...
CVE-2026-39170MEDIUM6.3SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POST request to /admin/semcms_user.php.
CVE-2026-39169HIGH7.5SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php.
CVE-2026-36823HIGH7.5Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the webAuthUserI...