CVE Vulnerability Database

Search and browse 397,994 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-39803HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denia...
CVE-2026-37430HIGH7.3An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allow...
CVE-2026-37429MEDIUM6.5qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysU...
CVE-2026-37428MEDIUM6.5qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysD...
CVE-2026-6177HIGH7.2The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and includi...
CVE-2026-42961MEDIUM5.1ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF token...
CVE-2026-42950MEDIUM5.1ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a ...
CVE-2026-42948MEDIUM4.8Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrato...
CVE-2026-42062CRITICAL9.8ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If process...
CVE-2026-40621CRITICAL9.8ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected produc...
CVE-2026-3426MEDIUM4.3The RTMKit Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing c...
CVE-2026-3425HIGH8.8The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in...
CVE-2026-35506HIGH8.6ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr par...
CVE-2026-25107MEDIUM6.9ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files...
CVE-2026-7168MEDIUM5.3Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and the...
CVE-2026-7009MEDIUM5.3When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify t...
CVE-2026-6429MEDIUM5.3When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password use...
CVE-2026-6276HIGH7.5Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done u...
CVE-2026-6253MEDIUM5.9curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following cond...
CVE-2026-5773HIGH7.5libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent ...
CVE-2026-5545MEDIUM6.5libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a...
CVE-2026-4873MEDIUM5.9A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the s...
CVE-2026-4798HIGH7.5The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in al...
CVE-2026-4782MEDIUM6.5The Avada Builder plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.15.2...
CVE-2026-44931MEDIUM5.1The newly introduced RecordUsage D-Bus method https://gitlab.freedesktop.org/pwithnall/malcontent/-/blob/0.14.0/libmalc...