CVE Vulnerability Database

Search and browse 397,817 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-10629HIGH7.4SIP signaling stack in Verizon IMS (unspecified version) implements SIP signaling without IPsec integrity protection (mi...
CVE-2026-10591HIGH8.8Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remot...
CVE-2026-10047HIGH7.8The Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the real-mode hook handler...
CVE-2026-10046HIGH7.8Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the BIOS INT 0x15 / E820 memor...
CVE-2026-9844HIGH8.8Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface mo...
CVE-2026-7313MEDIUM4.9CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 ...
CVE-2026-7312HIGH7.5CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152...
CVE-2026-7201HIGH8.8CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441...
CVE-2026-7198CRITICAL9.8CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unaut...
CVE-2026-7195HIGH8.1CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152,...
CVE-2026-49782MEDIUM5.4Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Acce...
CVE-2026-43965MEDIUM5.6Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/pa...
CVE-2026-42795MEDIUM5.1Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in th...
CVE-2026-41918MEDIUM5.9A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applicatio...
CVE-2026-39555HIGH8.1Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. This issue affects Askk...
CVE-2026-39553HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-39552HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-35717MEDIUM6.3A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows auth...
CVE-2026-32685MEDIUM4.6Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write...
CVE-2026-32250MEDIUM4.3NamelessMC is website software for Minecraft servers. A Reflected Cross-Site Scripting (XSS) vulnerability was discovere...
CVE-2026-28116MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Pr...
CVE-2026-27351MEDIUM5.4Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Configured Access Control ...
CVE-2026-10622HIGH8.2Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged fun...
CVE-2026-10621HIGH7.5Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archi...
CVE-2026-10611CRITICAL10An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In...