CVE Vulnerability Database

Search and browse 397,933 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-45187MEDIUM6.5Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users...
CVE-2026-41919CRITICAL9.1Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. Thi...
CVE-2026-35086MEDIUM6.5Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue a...
CVE-2026-31986CRITICAL9.1Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. U...
CVE-2026-31910HIGH7.5Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Us...
CVE-2026-31909HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issue affects Apache OFB...
CVE-2026-31906MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. Thi...
CVE-2026-31388MEDIUM5.3Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affects Apache OFBiz: bef...
CVE-2026-31387MEDIUM5.3Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are rec...
CVE-2026-31380MEDIUM6.5Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') v...
CVE-2026-31379MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname ...
CVE-2026-31378MEDIUM6.5Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are r...
CVE-2026-2611CRITICAL9.6In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. ...
CVE-2026-29226HIGH7.3Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations. This issue affects A...
CVE-2026-29220MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issu...
CVE-2026-29207MEDIUM6.5Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects...
CVE-2026-44408MEDIUM6.3There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an...
CVE-2026-8922MEDIUM5.4A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Key...
CVE-2026-4885CRITICAL9.8The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file typ...
CVE-2026-47317HIGH7.5Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Excessive Allocation. This issue affects Es...
CVE-2026-47316HIGH7.5Improper Check or Handling of Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Man...
CVE-2026-47315HIGH7.5Improper Check for Unusual or Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Man...
CVE-2026-47314CRITICAL9.8Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot:...
CVE-2026-47313HIGH7.5Memory allocation with excessive size value vulnerability in Samsung Open Source Escargot allows Excessive Allocation. ...
CVE-2026-47312HIGH7.5Release of invalid pointer or reference vulnerability in Samsung Open Source Escargot allows Buffer Manipulation. This ...