CVE Vulnerability Database

Search and browse 397,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-41963LOW2.8Stack overflow vulnerability in the media platform. Impact: Successful exploitation of this vulnerability may affect ava...
CVE-2026-41962LOW3.6Permission control vulnerability in the app management and control module. Impact: Successful exploitation of this vulne...
CVE-2026-41961MEDIUM5.9Permission control vulnerability in contacts. Impact: Successful exploitation of this vulnerability may affect availabil...
CVE-2026-41960MEDIUM5.8Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability...
CVE-2026-8425MEDIUM4.3The Notify Odoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2026-8398CRITICAL9.8A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 ...
CVE-2026-7563MEDIUM4.3The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to una...
CVE-2026-7046MEDIUM4.9The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to time-based blind SQL Injection...
CVE-2026-6415MEDIUM6.4The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u...
CVE-2026-6403HIGH7.5The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is...
CVE-2026-6228HIGH8.8The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and includ...
CVE-2026-5229CRITICAL9.8The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This...
CVE-2026-4683MEDIUM6.5The Smartcat Translator for WPML plugin for WordPress is vulnerable to unauthorized modification of data due to a missin...
CVE-2026-44088HIGH8.6SzafirHost verifies the signature of the downloaded JAR file using class JarInputStream (reading from the beginning of t...
CVE-2026-8654HIGH8.7Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operat...
CVE-2026-6646MEDIUM6.4The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all v...
CVE-2026-4094HIGH8.1The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss du...
CVE-2026-41702HIGH7VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a...
CVE-2026-43490HIGH8.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate inherited ACE SID length smb_inher...
CVE-2026-28761HIGH8.5Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 a...
CVE-2026-24662MEDIUM5.4Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and ear...
CVE-2026-0481CRITICAL9.2Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to per...
CVE-2025-54518HIGH7Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to...
CVE-2025-52532LOW2A race condition in the MxGPU-Virtualization driver’s ioctl path caused by concurrent unsynchronized access to the globa...
CVE-2024-36334HIGH7Improper verification of cryptographic signature in the Radeon RGB tool could allow a malicious file placed in the insta...