CVE Vulnerability Database

Search and browse 397,888 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-42506MEDIUM6.1Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged ...
CVE-2026-42502MEDIUM6.1Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged ...
CVE-2026-39821CRITICAL9.6The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For e...
CVE-2026-27136MEDIUM6.1Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged ...
CVE-2026-25681MEDIUM6.1Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged ...
CVE-2026-25680MEDIUM6.5Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
CVE-2022-34363HIGH7.5Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnerability in the  Unisp...
CVE-2022-31231HIGH7.5Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A...
CVE-2026-9256HIGH8.1NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists w...
CVE-2026-8992HIGH8.8An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenti...
CVE-2026-8353MEDIUM4.8Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inje...
CVE-2026-8347MEDIUM4.3Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog...
CVE-2026-8340MEDIUM4.3Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents perm...
CVE-2025-46371MEDIUM5.5Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability ...
CVE-2025-45145HIGH7.5Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 allows remote attac...
CVE-2025-32751MEDIUM5.5Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low...
CVE-2021-21508MEDIUM6.7Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Manager. A sys-admin u...
CVE-2026-9277HIGH8.1shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The ...
CVE-2026-8997MEDIUM4.8vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state file (vifminfo.json)...
CVE-2026-8673CRITICAL9.1Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Atta...
CVE-2026-8672MEDIUM5.1Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default User...
CVE-2026-8671HIGH7.5Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows R...
CVE-2026-8670CRITICAL9.6Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session ID...
CVE-2025-32749HIGH7.5Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerabilit...
CVE-2025-32747HIGH7.8Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged...