CVE Vulnerability Database

Search and browse 397,933 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-28732MEDIUM4.3Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word u...
CVE-2026-8788HIGH7.3Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections. The values from the set_add method were n...
CVE-2026-6342MEDIUM4.3Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to appropriately check for valid namespaces which allow...
CVE-2026-6341MEDIUM4.3Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to have API-level checks on which groups the user can c...
CVE-2026-6340MEDIUM6.5Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate 7zip archive structure befo...
CVE-2026-6334LOW3.8Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce client identity binding during the OAuth autho...
CVE-2026-4273MEDIUM4.3Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate that the RefreshedToken differs from the orig...
CVE-2026-3637MEDIUM4.3Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check the create_post channel permis...
CVE-2026-3495MEDIUM4.8Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious con...
CVE-2026-2325MEDIUM6.5Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to limit the size of the request body o...
CVE-2026-28759MEDIUM4.3Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has a...
CVE-2026-6495HIGH7.1The Ajax Load More WordPress plugin before 7.8.4 does not sanitise and escape a parameter before outputting it back in ...
CVE-2026-6381HIGH7.5The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowi...
CVE-2026-6379HIGH8.6The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before usin...
CVE-2026-3220HIGH8.8The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress...
CVE-2026-1631MEDIUM5.4The Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4 is vulnerable to unauth...
CVE-2026-8786MEDIUM6.3A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseFo...
CVE-2026-8785HIGH7.3A flaw has been found in projectworlds hospital-management-system-in-php 1.0. Affected by this vulnerability is the func...
CVE-2026-8784MEDIUM4.2A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected is the function change_file_status of the file c...
CVE-2026-8783MEDIUM4.3A security vulnerability has been detected in omec-project amf up to 2.1.3-dev. This impacts the function UERadioCapabil...
CVE-2026-8782MEDIUM4.3A weakness has been identified in omec-project amf up to 2.1.3-dev. This affects an unknown function of the file ngap/ha...
CVE-2026-8781MEDIUM4.3A security flaw has been discovered in omec-project amf up to 2.1.3-dev. The impacted element is the function RANConfigu...
CVE-2026-8780MEDIUM4.3A vulnerability was identified in omec-project amf up to 2.1.3-dev. The affected element is an unknown function of the f...
CVE-2026-8779MEDIUM4.3A vulnerability was determined in omec-project amf up to 2.1.3-dev. Impacted is the function NGSetupRequest of the file ...
CVE-2026-8777MEDIUM6.3A vulnerability was found in Edimax BR-6428NS 1.10. This issue affects the function formStaDrvSetup of the file /goform/...