CVE Vulnerability Database

Search and browse 397,888 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-32746MEDIUM5.5Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. An un...
CVE-2025-32745MEDIUM6.5Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthentica...
CVE-2025-26483HIGH8.2Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker c...
CVE-2026-44930CRITICAL9.8An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacke...
CVE-2026-44618MEDIUM5.3Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users a...
CVE-2026-44417HIGH7.5The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that anoth...
CVE-2026-5755MEDIUM6.5Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.2, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to ...
CVE-2026-5740HIGH7.5Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly validate ...
CVE-2026-5308HIGH7.5Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request bo...
CVE-2026-4646MEDIUM4.3Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate user-supp...
CVE-2026-4635MEDIUM5.3Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to archive the channe...
CVE-2026-3636MEDIUM4.3Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to sanitize team memb...
CVE-2026-3473HIGH7.1Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file owne...
CVE-2026-25608LOW2.3STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middl...
CVE-2026-25607MEDIUM5.7Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzin...
CVE-2026-25606HIGH8.7A SQL injection vulnerability has been identified in STER. Improper neutralization of input provided by user into multip...
CVE-2026-9011HIGH7.5The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass in al...
CVE-2026-8692MEDIUM4.3The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPress is vulnerable to...
CVE-2026-8684MEDIUM5.3The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includ...
CVE-2026-8679HIGH7.5The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including...
CVE-2026-8381MEDIUM5.4A broken access control vulnerability exists in the TeamViewer DEX Platform (On‑Premises) prior version 9.2. Certain bac...
CVE-2026-7798MEDIUM5.4The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin f...
CVE-2026-7636MEDIUM4.3The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable to Sensitive Informat...
CVE-2026-7615MEDIUM4.3The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2026-5072MEDIUM6.5A bitwise shift vulnerability in Zephyr's PTP subsystem allows a remote attacker to cause undefined behavior and potenti...