CVE Vulnerability Database

Search and browse 396,194 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-36784HIGH7.5Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in...
CVE-2026-36783HIGH7.5Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in...
CVE-2026-36779HIGH7.5Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain multiple stack over...
CVE-2026-36778MEDIUM4.9Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in...
CVE-2026-36777MEDIUM6.5Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in...
CVE-2026-36773MEDIUM6.5Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in...
CVE-2026-36772MEDIUM6.5Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in...
CVE-2026-36771HIGH7.5Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in...
CVE-2026-36770HIGH7.5Shenzhen Tenda Technology Co., Ltd Tenda US_W3V1.0BR v1.0.0.3 was discovered to contain a stack overflow in the Go param...
CVE-2026-36728MEDIUM5.4A markdown based cross-site scripting (XSS) vulnerability in the AI assistant chat function of FastapiAdmin v2.2.0 allow...
CVE-2026-36727CRITICAL9.1An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass...
CVE-2026-36726MEDIUM5.3An arbitrary file deletion vulnerability in the /api/delete-temp-license/{file} endpoint of bookcars v8.3 allows unauthe...
CVE-2026-36725MEDIUM6.1A markdown based cross-site scripting (XSS) vulnerability in the /system/notice/create endpoint of FastapiAdmin v2.2.0 a...
CVE-2026-36724MEDIUM6.5An uncaught exception in the /application/job/update/{id} endpoint of FastapiAdmin v2.2.0 allows authenticated attackers...
CVE-2026-36723HIGH8.8An unrestricted file rename vulnerability in the /api/create-user component of bookcars v8.3 allows authenticated attack...
CVE-2026-36722MEDIUM5.4An authenticated arbitrary file upload vulnerability in the /api/create-car-image component of bookcars v8.3 allows atta...
CVE-2026-36721CRITICAL9.8A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to ...
CVE-2026-36720HIGH8.1Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to admin via modif...
CVE-2026-36719HIGH7.5An information disclosure vulnerability in the /api/v1/user/info endpoint of AgentChat v2.3.0 allows unauthenticated att...
CVE-2026-30141CRITICAL9.8An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in the DecodeLZW function allows remote attack...
CVE-2026-10045CRITICAL9.8Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2.121, contains hardcoded ...
CVE-2025-55659MEDIUM6.5A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attacker...
CVE-2025-55658MEDIUM6.5GPAC MP4Box v2.4 was discovered to contain a floating point exception in the gf_opus_parse_packet_header function (media...
CVE-2025-55657HIGH7.5A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attack...
CVE-2025-55651MEDIUM5.5A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows...