CVE Vulnerability Database

Search and browse 397,925 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-9101MEDIUM4.3Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering she...
CVE-2026-9100HIGH7.1The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. ...
CVE-2026-9087HIGH8.1A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not ...
CVE-2026-8342——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-7613HIGH7.2The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0]...
CVE-2026-44926HIGH8.8InfoScale CmdServer before 7.4.2 mishandles access control.
CVE-2026-44925HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to for...
CVE-2026-44924MEDIUM5.4InfoScale VIOM 9.1.3 allows XSS.
CVE-2026-44923MEDIUM6.5SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges.
CVE-2026-20223CRITICAL10A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthentica...
CVE-2026-20206MEDIUM6.3A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, ...
CVE-2026-20199HIGH7.2A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, re...
CVE-2026-20171MEDIUM6.8A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switc...
CVE-2026-9084MEDIUM6MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based ...
CVE-2026-8598CRITICAL9.1An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not requi...
CVE-2026-8488HIGH7.5Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessi...
CVE-2026-8487HIGH7.5Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Da...
CVE-2026-8486HIGH7.5Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Floodin...
CVE-2026-5783HIGH7.6Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Beyaz Computer Sof...
CVE-2026-4293MEDIUM5.3The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be ...
CVE-2026-39047HIGH7.5Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Prin...
CVE-2025-32750HIGH7.5Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerabilit...
CVE-2023-7346MEDIUM4.1Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause i...
CVE-2026-8485HIGH7.5Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This i...
CVE-2026-8469HIGH8.2Allocation of Resources Without Limits or Throttling vulnerability in phenixdigital phoenix_storybook allows unauthentic...