CVE Vulnerability Database

Search and browse 397,836 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-48866CRITICAL9.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravit...
CVE-2026-48865HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPre...
CVE-2026-48839HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Stat...
CVE-2026-48559MEDIUM5.4Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers ...
CVE-2026-42683HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBookin...
CVE-2026-42682CRITICAL9.1Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Sec...
CVE-2026-42681HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf.Com e2pdf al...
CVE-2026-42680CRITICAL9.8Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows P...
CVE-2026-42251HIGH8.7Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server that hosted the applicat...
CVE-2026-37221HIGH7.5FlexRIC v2.0.0 crashes when receiving a RIC_SUBSCRIPTION_RESPONSE with an unknown ric_id that has no corresponding pendi...
CVE-2026-37220HIGH7.5FlexRIC v2.0.0 crashes when an SCTP association is closed before an E2_SETUP_REQUEST is sent. The near-RT RIC assumes a ...
CVE-2026-10533MEDIUM5A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQ...
CVE-2026-10267LOW3.3A security flaw has been discovered in janet-lang janet up to 1.41.0. This affects the function doframe of the file src/...
CVE-2026-10265MEDIUM6.3A vulnerability was identified in itsourcecode Content Management System 1.0. Affected by this issue is some unknown fun...
CVE-2026-10264LOW3.5A vulnerability was determined in lharries whatsapp-mcp 0.0.1. Affected by this vulnerability is the function SendMessag...
CVE-2026-10263HIGH7.3A vulnerability was found in SourceCodester Computer Repair Shop Management System up to 1.0. Affected is an unknown fun...
CVE-2026-10262HIGH7.3A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /l...
CVE-2026-10261HIGH7.3A flaw has been found in CodeAstro Online Job Portal 1.0. This affects an unknown function of the file /users/applicatio...
CVE-2026-10260HIGH7.3A vulnerability was detected in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file...
CVE-2026-10259HIGH8.8A security vulnerability has been detected in H3C Magic B0 up to 100R002. The affected element is the function SetMobile...
CVE-2026-0826CRITICAL9.2In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could en...
CVE-2025-60495MEDIUM5.5A segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box befo...
CVE-2025-60486MEDIUM5.5A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows at...
CVE-2025-60485MEDIUM5.5A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before...
CVE-2025-60483MEDIUM5.5A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Pro...