CVE Vulnerability Database

Search and browse 397,909 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-44055HIGH7.5A logic error involving bitwise OR operations in Netatalk 3.1.4 through 4.4.2 allows a remote authenticated attacker to ...
CVE-2026-44054MEDIUM6.5Netatalk 2.0.0 through 4.4.2 generates AFP session tokens derived from predictable process IDs, which allows a remote au...
CVE-2026-44053HIGH7.4Netatalk 1.5.0 through 4.2.2 uses a broken cryptographic algorithm in the DHCAST128 UAM, which allows a remote attacker ...
CVE-2026-44052HIGH7.5Netatalk 2.1.0 through 4.4.2 inserts LDAP simple-bind passwords into log output in cleartext, which allows an attacker w...
CVE-2026-44051HIGH8.1An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4.2 allows a remote authenticated attacker to read...
CVE-2026-44050CRITICAL9.9A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote auth...
CVE-2026-44049HIGH7.5An out-of-bounds write due to improper null termination in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a re...
CVE-2026-44048HIGH8.8A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a rem...
CVE-2026-44047HIGH8.8An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated a...
CVE-2026-6279CRITICAL9.8The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP F...
CVE-2026-2734MEDIUM6.5In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` G...
CVE-2026-1543MEDIUM6.4The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in ...
CVE-2026-4811MEDIUM4.9The WPB Floating Menu & Categories for WordPress – Sticky Side Menu with Icons plugin for WordPress is vulnerable to Sto...
CVE-2026-9152CRITICAL10A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search ind...
CVE-2026-48172CRITICAL9.8LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild i...
CVE-2026-1881MEDIUM4.3The Broadstreet plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includ...
CVE-2026-9149MEDIUM6.5A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted ...
CVE-2026-40165HIGH8.7authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 ...
CVE-2026-9150MEDIUM6.5A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser w...
CVE-2026-8399——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-47782MEDIUM4.6Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL v...
CVE-2026-47372CRITICAL9.1Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the buil...
CVE-2026-40102MEDIUM6.5Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-cont...
CVE-2026-40094MEDIUM4.3nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and prior, network...
CVE-2026-40092HIGH7.5nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and below, a malic...