CVE Vulnerability Database

Search and browse 397,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-46720HIGH8.2Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections. The metric names and set values were not ch...
CVE-2026-8759HIGH7.3A vulnerability was identified in xiandafu beetl up to 3.20.2. Affected is an unknown function of the file beetl-classic...
CVE-2026-8758HIGH7.3A vulnerability was determined in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This impacts an unknown function of the file...
CVE-2026-8757CRITICAL9.1A vulnerability was found in adenhq hive up to 0.11.0. This affects the function _read_events_tail of the file core/fram...
CVE-2026-8756HIGH7.3A vulnerability has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The impacted elem...
CVE-2026-8755HIGH7.3A flaw has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The affected element is th...
CVE-2026-8754MEDIUM6.3A vulnerability was detected in AstrBotDevs AstrBot up to 4.23.5. Impacted is the function post_file of the file astrbot...
CVE-2026-8753MEDIUM6.3A security vulnerability has been detected in kalcaddle Kodbox up to 1.64. This issue affects the function parseVideoInf...
CVE-2018-25339HIGH8.8Zechat 1.5 contains a SQL injection vulnerability in the v parameter that allows unauthenticated attackers to extract da...
CVE-2018-25338HIGH8.8Zechat 1.5 contains a SQL injection vulnerability in the hashtag parameter that allows unauthenticated attackers to extr...
CVE-2018-25337MEDIUM5.3Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized ...
CVE-2018-25336MEDIUM6.9jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user acco...
CVE-2018-25335CRITICAL9.8WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers...
CVE-2018-25334MEDIUM5.4Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's informa...
CVE-2018-25333HIGH8.8Nordex N149/4.0-4.5 Wind Turbine Web Server 4.0 contains an SQL injection vulnerability that allows unauthenticated atta...
CVE-2018-25332CRITICAL9.8GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitr...
CVE-2018-25331MEDIUM6.1Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to i...
CVE-2018-25330HIGH8.8Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow at...
CVE-2018-25329HIGH8.7WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers...
CVE-2018-25328HIGH8.6VX Search 10.6.18 contains a local buffer overflow vulnerability that allows attackers to overwrite the instruction poin...
CVE-2018-25327MEDIUM6.9Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform sta...
CVE-2018-25326HIGH8.7Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arb...
CVE-2018-25325HIGH8.7Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitra...
CVE-2018-25324MEDIUM6.9Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticat...
CVE-2018-25323HIGH8.6Allok AVI DivX MPEG to DVD Converter 2.6.1217 contains a structured exception handler buffer overflow vulnerability that...