CVE Vulnerability Database

Search and browse 397,909 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-9111HIGH8.8Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrar...
CVE-2026-9110MEDIUM4.2Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had...
CVE-2026-9102CRITICAL9.4A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitiza...
CVE-2026-9082CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core...
CVE-2026-47099MEDIUM6.1TeleJSON prior to 6.0.0 contains a DOM-based cross-site scripting vulnerability in the parse() function that allows atta...
CVE-2026-45444CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using M...
CVE-2026-39850HIGH7.4Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method V...
CVE-2026-39405CRITICAL9.4Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50....
CVE-2026-39352HIGH8.7Frappe is a full-stack web application framework. Versions prior to 15.105.0 and 16.15.0 contain a possible Arbitrary Fi...
CVE-2026-39311MEDIUM6.8Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas...
CVE-2026-39310HIGH8.6Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas...
CVE-2026-35016MEDIUM5.1Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in search.php that allows authen...
CVE-2026-35015MEDIUM5.1Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in do_unit_mail.php that allows ...
CVE-2026-35014MEDIUM5.1Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_nm.php that allows aut...
CVE-2026-35013MEDIUM5.1Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in street_view.php that allows a...
CVE-2026-35012MEDIUM5.1Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_facnote.php that allows a...
CVE-2026-35011MEDIUM5.1Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in opena.php that allows authent...
CVE-2026-35010MEDIUM5.1Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_JF.php that allows au...
CVE-2026-35009MEDIUM5.1Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_note.php that allows auth...
CVE-2026-35008MEDIUM5.1Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single.php that allows authen...
CVE-2026-35007MEDIUM5.1Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single_unit.php that allows a...
CVE-2026-33137CRITICAL9.3XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform ...
CVE-2026-2813MEDIUM4.1ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could e...
CVE-2026-2812MEDIUM5.3ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthent...
CVE-2026-26028MEDIUM6.1CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the HTML sanitizer in Dif...