CVE Vulnerability Database

Search and browse 397,697 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-5068HIGH8.8A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SD...
CVE-2026-44083CRITICAL9.8An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attack...
CVE-2026-41986LOW2.4Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availabi...
CVE-2026-41985MEDIUM5.1UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect ser...
CVE-2026-41984MEDIUM5.2UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect ser...
CVE-2026-41983MEDIUM4.3Null pointer dereference vulnerability in the browser module. Impact: Successful exploitation of this vulnerability may ...
CVE-2026-41982MEDIUM6.4Race condition vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availab...
CVE-2026-41981MEDIUM5.3Out-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect av...
CVE-2026-41977MEDIUM5DoS vulnerability in the log service. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-41976MEDIUM6.6Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vulnerability may affec...
CVE-2026-41974LOW3.6Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may aff...
CVE-2026-41973MEDIUM5.9Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability...
CVE-2026-41972MEDIUM5.4Path traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability may affect availabili...
CVE-2025-62858MEDIUM6.5A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker...
CVE-2026-8981LOW3.5The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability acros...
CVE-2026-5067CRITICAL9.8A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sendi...
CVE-2026-4986MEDIUM5.3The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before ...
CVE-2026-41539MEDIUM6.1A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remot...
CVE-2026-11572HIGH8.8Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to impro...
CVE-2026-9662HIGH8.1The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and in...
CVE-2026-9185HIGH7.5The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versi...
CVE-2026-8977MEDIUM6.4The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_ac...
CVE-2026-8940MEDIUM4.3The WP Meta Sort Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2026-8910MEDIUM6.1The WP Emoticon Rating plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2026-8909MEDIUM4.3The WpMobi plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.3....