CVE Vulnerability Database

Search and browse 397,801 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-50224MEDIUM4.9The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall l...
CVE-2026-50214CRITICAL9.8The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary...
CVE-2026-4881MEDIUM6.5In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being...
CVE-2026-49771HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Galler...
CVE-2026-49510MEDIUM6.1Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects ...
CVE-2026-47320MEDIUM6.1Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Mani...
CVE-2026-47319MEDIUM6.1Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. T...
CVE-2026-47318MEDIUM6.1Stack-based buffer overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rl...
CVE-2026-47306MEDIUM6.1Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This iss...
CVE-2026-10800LOW3.6A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_featu...
CVE-2026-10305MEDIUM6.1Out-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: be...
CVE-2026-50213HIGH7.5The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled b...
CVE-2026-50212MEDIUM6.5Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user...
CVE-2026-50211CRITICAL9.8Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious...
CVE-2026-50210HIGH7.5The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to re...
CVE-2026-50209HIGH7.8Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint addres...
CVE-2026-50208CRITICAL9.4High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric enc...
CVE-2026-50207HIGH7.8The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read base...
CVE-2026-3820HIGH7.2There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR.  An attacker may obtain admini...
CVE-2026-50206MEDIUM6.8Incoming VPN network profile settings fail to process special characters safely, enabling command injection via maliciou...
CVE-2026-50205HIGH8.2System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identifi...
CVE-2026-49204MEDIUM6.5Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.
CVE-2026-49203HIGH8.3Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote prof...
CVE-2026-49202HIGH8.6Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource S...
CVE-2026-49194HIGH8.8The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and dire...