CVE Vulnerability Database

Search and browse 397,697 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-25558MEDIUM4.8QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authent...
CVE-2026-11521MEDIUM6.3A security vulnerability has been detected in Mohammed-eid35 bank-management-system-springboot up to 7b9bcc65ad7df3db29a...
CVE-2026-11520LOW3.5A weakness has been identified in SourceCodester Inventory System 1.0. Affected by this issue is some unknown functional...
CVE-2026-11519MEDIUM6.3A security flaw has been discovered in SourceCodester Inventory System 1.0. Affected by this vulnerability is an unknown...
CVE-2026-11518MEDIUM4.3A vulnerability was identified in SourceCodester Inventory System 1.0. Affected is an unknown function of the file /user...
CVE-2026-11517HIGH8.8A vulnerability was determined in UTT HiPER 2610G up to 3.0.0-171107. This impacts the function strcpy of the file /gofo...
CVE-2026-11516MEDIUM5.5A vulnerability was found in UTT HiPER 2610G up to 3.0.0-171107. This affects the function strcpy of the file /goform/fo...
CVE-2026-9549MEDIUM4.8Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and ...
CVE-2026-8833MEDIUM5.4Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0...
CVE-2026-8078MEDIUM4.8Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 v...
CVE-2026-7765MEDIUM5.3Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints ...
CVE-2026-7186MEDIUM5.4Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 version...
CVE-2026-11577——Rejected reason: The reported behavior does not constitute a privilege escalation. Exploitation requires the attacker to...
CVE-2026-11515MEDIUM5.5A vulnerability has been found in SourceCodester Barangay Resident Profiling and Information Management System 1.0. The ...
CVE-2026-11514MEDIUM6.3A flaw has been found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the...
CVE-2026-11513MEDIUM6.3A vulnerability was detected in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file...
CVE-2026-11512MEDIUM4.3A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This issue affects some unkno...
CVE-2026-11511LOW3.5A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/...
CVE-2026-50752HIGH7.4A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacke...
CVE-2026-50751CRITICAL9.3A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows ...
CVE-2026-47430HIGH7.5## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body ...
CVE-2026-3011MEDIUM6.4The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'su...
CVE-2026-11569MEDIUM5.4A flaw was found in Quay. The filedrop endpoint accepts any mime type without validation, allowing an authenticated user...
CVE-2026-11510MEDIUM6.3A security flaw has been discovered in CodeAstro Leave Management System 1.0. This affects an unknown part of the file /...
CVE-2026-11509MEDIUM6.3A vulnerability was identified in CodeAstro Leave Management System 1.0. Affected by this issue is some unknown function...