CVE Vulnerability Database

Search and browse 397,864 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-48968MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slid...
CVE-2026-48877MEDIUM6.5Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retrieve Embedded Sensitive...
CVE-2026-40852HIGH7.2A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. T...
CVE-2026-40851HIGH8.4A local attacker can perform a confusion attack on the cfgparser via a specially crafted file on an USB stick leading to...
CVE-2026-40850HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountData func...
CVE-2026-40849HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the user_alarmprofile vi...
CVE-2026-40848HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the tag view due to impr...
CVE-2026-40847HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system_tag view due ...
CVE-2026-40846HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system view due to i...
CVE-2026-40845HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the devices_configuratio...
CVE-2026-40844HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dashboard view due t...
CVE-2026-40843HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the alarming view due to...
CVE-2026-40842HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getWidgetTags functi...
CVE-2026-40841HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectTags funct...
CVE-2026-40840HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the VerifyCreateLicences...
CVE-2026-40839HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getComponentScalings...
CVE-2026-40838HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDeviceScalings fu...
CVE-2026-40837HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectScalings f...
CVE-2026-40836HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the inmessage model due ...
CVE-2026-40835HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the saveObjectFromData f...
CVE-2026-40834HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash_layout.php file...
CVE-2026-40833HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash.php files saveD...
CVE-2026-40832HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDevicegroups func...
CVE-2026-40831HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the Easy View due to imp...
CVE-2026-40830HIGH7A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the admin.mbnetj.php fil...