CVE Vulnerability Database

Search and browse 397,845 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-10074MEDIUM6.9DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to explo...
CVE-2026-10073HIGH8.7DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing unauthenticated local attackers to ...
CVE-2026-10072HIGH8.6DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to up...
CVE-2026-10061CRITICAL9.8A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. ...
CVE-2026-10060CRITICAL9.8A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /gofor...
CVE-2026-9509HIGH8.7An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated...
CVE-2026-9508CRITICAL10Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow bac...
CVE-2026-8326CRITICAL10Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitra...
CVE-2026-49324MEDIUM4.6Uncontrolled resource consumption in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025...
CVE-2026-49323MEDIUM4.3Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcyc...
CVE-2026-48527HIGH8.7HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by...
CVE-2026-45611——Rejected reason: Further research determined the issue is not a vulnerability.
CVE-2026-45551MEDIUM5.1Group-Office is an enterprise customer relationship management and groupware tool. Prior to 26.0.25, 25.0.100, and 6.8.1...
CVE-2026-45312CRITICAL9.9RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injectio...
CVE-2026-45043CRITICAL9.3RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rust...
CVE-2026-10071CRITICAL9.8DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers ...
CVE-2026-9811MEDIUM5.4A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering s...
CVE-2026-9809HIGH7.6A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project ...
CVE-2026-9808HIGH7.1An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain co...
CVE-2026-9559CRITICAL9.9A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files dur...
CVE-2025-41281HIGH7.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41280HIGH7.8Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9....
CVE-2025-41279HIGH7.2Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41278HIGH7.8Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R260114104...
CVE-2025-41277CRITICAL9.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...