CVE Vulnerability Database

Search and browse 397,801 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-10783LOW2.5A security flaw has been discovered in gradio-app gradio 6.14.0. This affects the function save_audio_to_cache of the co...
CVE-2026-2596——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-10777HIGH7.3A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Af...
CVE-2026-10775MEDIUM5.3A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_h...
CVE-2026-46447HIGH7.7OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info o...
CVE-2026-22055HIGH8.8Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low p...
CVE-2026-22054HIGH8.8Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with l...
CVE-2026-10771HIGH7.3A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-...
CVE-2026-50033HIGH7.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock D...
CVE-2026-44682HIGH7.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock D...
CVE-2026-44609HIGH7.3Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock D...
CVE-2026-43924MEDIUM4.8FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Redirect module doe...
CVE-2026-42061HIGH7.3Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected...
CVE-2026-40495MEDIUM6.9FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 leak the exact system v...
CVE-2026-37700MEDIUM4.1Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via t...
CVE-2026-26825MEDIUM5.3A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reacha...
CVE-2026-26824MEDIUM6.5libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser. Memory al...
CVE-2026-10766LOW3.6A vulnerability has been found in mlrun up to 1.12.0-rc3. This impacts the function mlrun.utils.helpers.calculate_datafr...
CVE-2026-8889HIGH7.5Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) an...
CVE-2026-8888HIGH7.5Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as J...
CVE-2026-8881HIGH7.5Version 3.0.7 of the Securly Chrome Extension uses EVP_BytesToKey key derivation with MD5 and a single iteration for AES...
CVE-2026-8879HIGH7.5Version 3.0.7 of the Securly Chrome Extension dynamically registers content13.min.js as a content script via chrome.scri...
CVE-2026-8878HIGH7.5Version 3.0.7 of the Securly Chrome Extension exposes multiple publicly accessible endpoints that allow unauthenticated ...
CVE-2026-8876HIGH7.3Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js. These key...
CVE-2026-8874HIGH7.1Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules ...