CVE Vulnerability Database

Search and browse 397,888 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-6898HIGH8.8The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2026-6897HIGH8.8The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2026-6895HIGH8.8The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclos...
CVE-2026-6419HIGH8.8The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up ...
CVE-2026-47280CRITICAL9.8Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a net...
CVE-2026-45659HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2026-42901CRITICAL10Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-42827HIGH7.5Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz...
CVE-2026-41149MEDIUM5.3Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 ...
CVE-2026-41148MEDIUM5.3Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 ...
CVE-2026-41104HIGH7.5Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose inform...
CVE-2026-41090CRITICAL9.3Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut...
CVE-2026-40412CRITICAL9.8Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code ...
CVE-2026-40411HIGH8.8Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.
CVE-2026-35430HIGH8.8Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized atta...
CVE-2026-33843CRITICAL9.8Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized ...
CVE-2026-26147HIGH7.7Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
CVE-2026-23663HIGH7.5Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-23652CRITICAL9.8Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an u...
CVE-2026-41147HIGH8.7NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS)...
CVE-2026-41076HIGH8.1RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 t...
CVE-2026-41075HIGH8.8RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through ...
CVE-2026-41074HIGH7.1RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Si...
CVE-2026-41073MEDIUM4.6RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0....
CVE-2026-41071HIGH8.1libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file w...