CVE Vulnerability Database

Search and browse 396,317 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-33113MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-32193HIGH8.8Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service all...
CVE-2026-28301MEDIUM4.8A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended websit...
CVE-2026-26142CRITICAL9.8Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.
CVE-2026-24181HIGH7.3NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A succes...
CVE-2026-24180HIGH7.3NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A succes...
CVE-2026-22926HIGH7.8Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.
CVE-2026-0420MEDIUM5.9An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which co...
CVE-2026-0419HIGH8Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows u...
CVE-2026-0418MEDIUM4.5Insufficient configuration management in the listed devices allows authenticated administrators connected to the local n...
CVE-2026-0417MEDIUM4.5Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected ...
CVE-2026-0416MEDIUM4.5An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated admini...
CVE-2026-0415MEDIUM4.5Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t...
CVE-2026-0414MEDIUM4.5Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t...
CVE-2026-0413MEDIUM4.5A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated a...
CVE-2026-0412MEDIUM4.5Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in ...
CVE-2026-0411HIGH8An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected...
CVE-2026-0410MEDIUM4.5Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorize...
CVE-2026-0409MEDIUM6.4A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the rout...
CVE-2026-8045MEDIUM6.5CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosu...
CVE-2026-8025CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information T...
CVE-2026-49948HIGH8.6Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted s...
CVE-2026-49938MEDIUM6.5A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, Fo...
CVE-2026-25089CRITICAL9.8A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F...
CVE-2026-24065HIGH8.1Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privile...