CVE Vulnerability Database

Search and browse 397,819 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-48570HIGH7.8In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from the background due to...
CVE-2025-32348HIGH7.8In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead...
CVE-2025-26418HIGH7.8In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when ...
CVE-2025-22426HIGH7.8In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in th...
CVE-2025-22424HIGH7.8In multiple locations, there is a possible way to reveal images across users due to improper input validation. This coul...
CVE-2019-25716HIGH7.5Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote...
CVE-2018-25435MEDIUM6.9ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions o...
CVE-2018-25434HIGH8.8WP AutoSuggest 0.24 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S...
CVE-2018-25433HIGH8.8Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to e...
CVE-2018-25432HIGH8.6Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwri...
CVE-2018-25431HIGH7.1No-Cms 1.0 contains an SQL injection vulnerability in the order_by parameter of the manage_privilege export endpoint tha...
CVE-2018-25430HIGH7.1Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL que...
CVE-2018-25429HIGH7.1Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL que...
CVE-2018-25428HIGH8.8Paroiciel 11.20 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL q...
CVE-2018-25427CRITICAL9.8Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary co...
CVE-2026-5419LOW3.7A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing si...
CVE-2026-49433MEDIUM5The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSRF protection. If an ...
CVE-2026-49140MEDIUM5.3Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the Matrix channel media download handler t...
CVE-2026-49139HIGH7Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handl...
CVE-2026-49138MEDIUM5.3Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows re...
CVE-2026-49136HIGH8.7Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() ...
CVE-2026-49135HIGH7.2CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to acces...
CVE-2026-49134HIGH7.5CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers ...
CVE-2026-37234HIGH8.2FlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp_ids by sending multiple E42_SETUP_REQUESTs. On disc...
CVE-2026-24751HIGH8.2Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Dat...