CVE Vulnerability Database

Search and browse 397,925 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-8467CRITICAL9.5Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanit...
CVE-2026-47068LOW2.3Authorization Bypass Through User-Controlled Key vulnerability in phenixdigital phoenix_storybook allows cross-session P...
CVE-2026-24425CRITICAL9.9Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface ...
CVE-2026-22554HIGH7.8A heap-based buffer overflow vulnerability exists in the Channel Splitting functionality of MediaInfoLib (version(s): 26...
CVE-2026-21836MEDIUM6.5The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability.  Under certain circumstances, documen...
CVE-2026-5950MEDIUM5.3An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling ...
CVE-2026-5947MEDIUM5.9Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incomi...
CVE-2026-5946HIGH7.5Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`...
CVE-2026-45584HIGH8.1Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
CVE-2026-45498HIGH7.5Microsoft Defender Denial of Service Vulnerability
CVE-2026-45443MEDIUM5Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Explo...
CVE-2026-42834HIGH7.8Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
CVE-2026-42383HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITH YITH WooComme...
CVE-2026-41091HIGH7.8Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to el...
CVE-2026-3593CRITICAL9.8A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20....
CVE-2026-3592MEDIUM5.3BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a quer...
CVE-2026-3039HIGH7.5BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory ...
CVE-2026-29518HIGH7Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that ...
CVE-2026-27424MEDIUM4.3Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Confi...
CVE-2026-27405MEDIUM6.5Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Contr...
CVE-2026-24573MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualiz...
CVE-2025-11954HIGH8Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross S...
CVE-2025-31985MEDIUM6.5HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Ty...
CVE-2025-31973CRITICAL9.8HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outd...
CVE-2026-25602LOW2.3Insufficient Verification of Data Authenticity in the feedback function of Mesalvo MEONA (MEONA Client and MEONA Server)...