CVE Vulnerability Database

Search and browse 397,845 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-41276CRITICAL9.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41275CRITICAL9.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41274CRITICAL9.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41273CRITICAL9.8Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI...
CVE-2025-41272CRITICAL9.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41271HIGH7.5Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hos...
CVE-2025-41270CRITICAL9.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41269CRITICAL9.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41268CRITICAL9.1Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and...
CVE-2025-41267HIGH7.2Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41266HIGH7.2Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41265HIGH7.2Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2026-9558CRITICAL9.9A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twi...
CVE-2026-9557MEDIUM6.4A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of...
CVE-2026-49201CRITICAL9.8The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows a...
CVE-2026-46579HIGH7.5A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP fronte...
CVE-2026-42965MEDIUM6.5A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creat...
CVE-2026-10078LOW2.7A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, spec...
CVE-2025-12714MEDIUM5.3The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due ...
CVE-2026-9189MEDIUM5.3The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verifi...
CVE-2026-6075HIGH8.1The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl...
CVE-2026-49200CRITICAL9.8The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file conta...
CVE-2026-49199CRITICAL9.8Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.
CVE-2026-49198MEDIUM4.9Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorize...
CVE-2026-49197CRITICAL9.8Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requ...