CVE Vulnerability Database

Search and browse 397,790 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-41236HIGH8.8Froxlor is open source server administration software. Version 2.3.6 contains a symlink-following flaw in the root-owned...
CVE-2026-41235HIGH8.6Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_she...
CVE-2026-41234HIGH7.6Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does n...
CVE-2026-40898HIGH7.5quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory...
CVE-2026-36499MEDIUM6.5A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB wr...
CVE-2025-71316CRITICAL9.8SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANS...
CVE-2025-65640MEDIUM6.3Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5....
CVE-2026-50292CRITICAL9.8In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properti...
CVE-2026-48040CRITICAL9.1The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivious HTTP (RFC 9458) ...
CVE-2026-41207MEDIUM5.3The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.21.Final, HKDF_expand return...
CVE-2026-25551HIGH7.8Seagull Software BarTender 2021 R1 through 12.0.1 contains an insecure deserialization vulnerability that allows low-pri...
CVE-2026-25550CRITICAL9.8Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .N...
CVE-2026-10880CRITICAL9.8OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly ...
CVE-2026-10796HIGH7.5nvm (Node Version Manager) through 0.40.4 executes arbitrary commands from version strings supplied by the configured No...
CVE-2025-69755HIGH8.2An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and ...
CVE-2025-67448HIGH7.1The SMS module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to stored XSS. The application does not...
CVE-2025-67447CRITICAL9.8The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command inje...
CVE-2026-50266LOW2.2In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another p...
CVE-2026-50076CRITICAL9.1Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Jav...
CVE-2026-49942HIGH7.3Net::CIDR::Set versions through 0.20 for Perl did not validate network masks. The mask portion of a network mask could ...
CVE-2026-49941HIGH7.5Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses. The add method called the _encode method t...
CVE-2026-49940MEDIUM6.5Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks. Unicode digits such as the Ar...
CVE-2026-46741HIGH7.5Etsy::StatsD versions through 1.002002 for Perl allow metric injections. The metric names and values are not checked fo...
CVE-2026-46739MEDIUM5.3Net::Statsd versions before 0.13 for Perl allow metric injections. The metric names are not checked for newlines, colon...
CVE-2025-67446CRITICAL9.8Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router u...