CVE Vulnerability Database

Search and browse 397,801 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2019-25731MEDIUM6.1Zuz Music 2.1 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject m...
CVE-2019-25730HIGH8.8Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ...
CVE-2019-25729CRITICAL9.8PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute ...
CVE-2019-25728HIGH8.8Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL...
CVE-2019-25727CRITICAL9.8WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated atta...
CVE-2019-25726HIGH8.8All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute...
CVE-2026-4104CRITICAL9.8Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and ...
CVE-2026-45432HIGH8.7This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in i...
CVE-2026-45431HIGH8.7This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic ...
CVE-2026-10843HIGH7.2A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are pro...
CVE-2026-10840HIGH7.1A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the sys...
CVE-2026-10804MEDIUM4.7A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/r...
CVE-2026-10803LOW3.6A flaw has been found in MLflow up to 3.10.0. This issue affects the function mlflow.data.digest_utils of the file mlflo...
CVE-2026-10802MEDIUM4.3A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the libra...
CVE-2025-52612HIGH8.8HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site script...
CVE-2025-52611MEDIUM4.3HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to ...
CVE-2025-52609MEDIUM5.3HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by...
CVE-2025-52608MEDIUM4.3HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing s...
CVE-2025-52606MEDIUM4.3HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an ar...
CVE-2025-12694HIGH7.8A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user t...
CVE-2026-49077MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMembe...
CVE-2026-10801LOW3.6A security vulnerability has been detected in modelscope ms-swift up to 4.2.0. This affects the function Template._save_...
CVE-2026-8916MEDIUM6.1Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: b...
CVE-2026-50226MEDIUM5.3Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrar...
CVE-2026-50225CRITICAL9.1The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems t...