CVE Vulnerability Database

Search and browse 397,873 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-7310MEDIUM4.4A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious ...
CVE-2026-48136MEDIUM4.1When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access...
CVE-2026-48135MEDIUM5.3A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request pa...
CVE-2026-48134MEDIUM5.6When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific...
CVE-2026-48133HIGH7.5When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to r...
CVE-2026-48132HIGH8.1The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As...
CVE-2026-48131HIGH8.1The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage o...
CVE-2025-11482HIGH8.7An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in PPT30 Operating Syst...
CVE-2026-44410LOW3.8This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended...
CVE-2026-39661HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-39642MEDIUM5.3Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabRice Nyla allows Code...
CVE-2026-27427MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mas...
CVE-2026-25713HIGH7.8A heap-based buffer overflow vulnerability exists in the ID3v2 parsing functionality of MediaInfoLib (version(s): 26.01)...
CVE-2026-25104HIGH7.8A heap-based buffer overflow vulnerability exists in the LXF parsing functionality of MediaInfoLib (version(s): 26.01). ...
CVE-2026-24638MEDIUM4.3Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Cont...
CVE-2026-24590MEDIUM5.3Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Config...
CVE-2026-8047HIGH8.7The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited ...
CVE-2026-8046HIGH8.1The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged ...
CVE-2026-44469HIGH7The affected product extracts installation files to a temporary directory with incorrect default permissions during admi...
CVE-2026-44468HIGH8.5The affected product creates a directory with insecure default permissions during administrative installation. This allo...
CVE-2026-39655MEDIUM5.3Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control...
CVE-2026-9534MEDIUM6.3A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cs...
CVE-2026-9533MEDIUM6.3A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of th...
CVE-2026-9532MEDIUM6.3A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploa...
CVE-2026-9496HIGH7.7Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha...