CVE Vulnerability Database

Search and browse 397,925 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-8706MEDIUM6.5Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same devi...
CVE-2026-5804HIGH8.4An improper authentication vulnerability was discovered in the Motorola Factory Test component (com.motorola.motocit). T...
CVE-2026-37281CRITICAL9.8An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remo...
CVE-2026-31072CRITICAL9.8The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remot...
CVE-2026-31071CRITICAL9.1API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated...
CVE-2026-31070CRITICAL9.8The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileg...
CVE-2026-31069HIGH8.8BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlle...
CVE-2026-30118CRITICAL9.8scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of...
CVE-2026-30117CRITICAL9.8scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parame...
CVE-2026-8711CRITICAL9.8NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled...
CVE-2026-47100HIGH8.7Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public c...
CVE-2026-45557MEDIUM6.9Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in con...
CVE-2026-44159CRITICAL9.8Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the c...
CVE-2026-43634HIGH8.7HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote attackers ...
CVE-2026-34883MEDIUM5.3An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell monitors. On Windows, a ...
CVE-2026-2587CRITICAL9.6A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used...
CVE-2026-2586CRITICAL9.1An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user ...
CVE-2025-70950HIGH7.3An issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a crafted request.
CVE-2025-51427HIGH7.3An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in t...
CVE-2026-8975HIGH8.8Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence...
CVE-2026-8974HIGH8.8Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruptio...
CVE-2026-8973HIGH8.8Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2026-8972HIGH8.8Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 1...
CVE-2026-8971MEDIUM6.5Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird ...
CVE-2026-8970HIGH8.8Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunder...