CVE Vulnerability Database

Search and browse 397,870 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-9551HIGH7.3A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of ...
CVE-2026-9550HIGH7.3A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0....
CVE-2026-4480CRITICAL9A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the comma...
CVE-2026-46368HIGH8.8luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distribu...
CVE-2026-45247CRITICAL9.8Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that ...
CVE-2026-45082HIGH7.6Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability...
CVE-2026-43919——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43918. Reason: This candidate is a ...
CVE-2026-42785HIGH8.6OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitra...
CVE-2026-42425HIGH8.6OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to exe...
CVE-2026-42347——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-28496. Reason: This candidate is a ...
CVE-2026-41917MEDIUM6.9OpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interface at /admin/Scriptin...
CVE-2026-41401HIGH7.1libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly up...
CVE-2026-40034HIGH8.5gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmo...
CVE-2026-40033HIGH8.8FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers t...
CVE-2026-9544HIGH7.3A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by thi...
CVE-2026-9543CRITICAL9.8A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the fi...
CVE-2026-9542MEDIUM6.3A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of ...
CVE-2026-9541MEDIUM5.3A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqob...
CVE-2026-9540MEDIUM5.5A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component ...
CVE-2026-8479MEDIUM6.9IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially craf...
CVE-2026-8174MEDIUM5.7Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wo...
CVE-2026-7374CRITICAL9.9A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with ed...
CVE-2026-7310MEDIUM4.4A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious ...
CVE-2026-48136MEDIUM4.1When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access...
CVE-2026-48135MEDIUM5.3A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request pa...