CVE Vulnerability Database

Search and browse 397,801 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-49193HIGH7.5Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the...
CVE-2026-49192MEDIUM5.4The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware seri...
CVE-2026-49191CRITICAL9.8The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose...
CVE-2026-49190HIGH8.8The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unau...
CVE-2026-50219MEDIUM5.9libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_Pars...
CVE-2026-49189HIGH7.8Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke ...
CVE-2026-49188CRITICAL9.8The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for u...
CVE-2026-49187HIGH7.5The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
CVE-2026-10805MEDIUM6.7A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient ba...
CVE-2026-49186CRITICAL9.8The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe usin...
CVE-2026-49185CRITICAL9.8The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction...
CVE-2026-48681HIGH8.1OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted IS...
CVE-2026-44917MEDIUM4.9OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Iron...
CVE-2026-41283CRITICAL9.9OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints tha...
CVE-2026-41010HIGH8.7ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "...
CVE-2026-8829HIGH7.5HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS routine backing HTML::E...
CVE-2026-41860HIGH8.8CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpReq...
CVE-2026-41859HIGH7.8A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth heade...
CVE-2026-41858HIGH7.5Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities...
CVE-2026-41011HIGH8.7PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz")...
CVE-2026-10597MEDIUM6.9OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote a...
CVE-2026-8653MEDIUM6.5The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in ...
CVE-2026-7764MEDIUM6.8An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versio...
CVE-2026-10737HIGH7.5The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability ...
CVE-2026-8722MEDIUM6.5Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked fo...