CVE Vulnerability Database

Search and browse 397,814 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-42061HIGH7.3Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected...
CVE-2026-40495MEDIUM6.9FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 leak the exact system v...
CVE-2026-37700MEDIUM4.1Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via t...
CVE-2026-26825MEDIUM5.3A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reacha...
CVE-2026-26824MEDIUM6.5libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser. Memory al...
CVE-2026-10766LOW3.6A vulnerability has been found in mlrun up to 1.12.0-rc3. This impacts the function mlrun.utils.helpers.calculate_datafr...
CVE-2026-8889HIGH7.5Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) an...
CVE-2026-8888HIGH7.5Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as J...
CVE-2026-8881HIGH7.5Version 3.0.7 of the Securly Chrome Extension uses EVP_BytesToKey key derivation with MD5 and a single iteration for AES...
CVE-2026-8879HIGH7.5Version 3.0.7 of the Securly Chrome Extension dynamically registers content13.min.js as a content script via chrome.scri...
CVE-2026-8878HIGH7.5Version 3.0.7 of the Securly Chrome Extension exposes multiple publicly accessible endpoints that allow unauthenticated ...
CVE-2026-8876HIGH7.3Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js. These key...
CVE-2026-8874HIGH7.1Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules ...
CVE-2026-7888HIGH8.4Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and ...
CVE-2026-45702MEDIUM5.5OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-45614MEDIUM4.7OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-42840MEDIUM5.1An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and...
CVE-2026-42839MEDIUM4.8An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScript in the item_name, ...
CVE-2026-26379MEDIUM6.5Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configura...
CVE-2026-26378MEDIUM5.4Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file ...
CVE-2026-46273HIGH8.6In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS So...
CVE-2026-46272MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: coresight: tmc-etr: Fix race condition between sysf...
CVE-2026-46271HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: do WoW offloads only on primary link ...
CVE-2026-46270HIGH8.4In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: Fix use-after-free in power_...
CVE-2026-46269MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: pinctrl: canaan: k230: Fix NULL pointer dereference...