CVE Vulnerability Database

Search and browse 397,888 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-9264CRITICAL9.3A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution an...
CVE-2026-34911HIGH7.7A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in Un...
CVE-2026-34910CRITICAL10A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS ...
CVE-2026-34909CRITICAL10A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to a...
CVE-2026-34908CRITICAL10A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS de...
CVE-2026-33000CRITICAL9.1A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit...
CVE-2026-5297——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-8435MEDIUM6.5Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file appr...
CVE-2026-8434HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file resc...
CVE-2026-8433HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file resc...
CVE-2026-8432HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star...
CVE-2026-8427HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file remo...
CVE-2026-8416HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addF...
CVE-2026-8415HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/as...
CVE-2026-8414HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/dupl...
CVE-2026-8413HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/...
CVE-2026-8412HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk...
CVE-2026-8411HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/...
CVE-2026-8410HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/...
CVE-2026-8409HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delet...
CVE-2026-8337MEDIUM5.3Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in s...
CVE-2026-8327MEDIUM4.3Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass...
CVE-2026-8245MEDIUM5.4Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection. Concrete\...
CVE-2026-8240MEDIUM5.3Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure across every page with a configur...
CVE-2026-8239MEDIUM5.3Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/get_rating' endpoint confirms exist...