CVE Vulnerability Database

Search and browse 397,925 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-8370HIGH8.5Execution with unnecessary privileges vulnerability in Broadcom Automic Automation Agent Unix on Linux x64, Linux Power ...
CVE-2026-8096MEDIUM6.5The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypa...
CVE-2026-8073HIGH7.5The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file del...
CVE-2026-41470HIGH8.2LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows at...
CVE-2026-34154MEDIUM5.3Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1...
CVE-2026-33741MEDIUM6.8EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated use...
CVE-2026-33642CRITICAL9.8Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kit...
CVE-2026-33637MEDIUM6.5Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Versions 2.0.0 ...
CVE-2026-32738MEDIUM6.5libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequen...
CVE-2026-8605CRITICAL9.8In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA syst...
CVE-2026-8604HIGH8.8In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a vic...
CVE-2026-8603CRITICAL9.8In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on t...
CVE-2026-8602CRITICAL9.1In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated at...
CVE-2026-6009HIGH8.7Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allow...
CVE-2026-47107HIGH8.6Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files ...
CVE-2026-33633HIGH8.8Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_dat...
CVE-2026-32134MEDIUM5.9NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below, when NanoMQ handles...
CVE-2025-61081——Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-5511LOW2.7In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user i...
CVE-2026-47358HIGH8.6Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded...
CVE-2026-47357HIGH8.6Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the rem...
CVE-2026-47356HIGH8.6Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the fi...
CVE-2026-36829CRITICAL9.8An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7....
CVE-2026-36828HIGH8.8A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and includin...
CVE-2026-36827MEDIUM5.4A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface inv...