CVE Vulnerability Database

Search and browse 397,994 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-41051MEDIUM5.1csync2 uses insecure temporary directories when compiled with C99 or later, allowing for TOCTOU style attacks on the tem...
CVE-2026-2515MEDIUM5.3The Hostinger Reach – AI-Powered Email Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modifi...
CVE-2026-25710HIGH7The new upstream added a privileged D-Bus helper called plasmaloginauthhelper, which suffers from multiple issues, e.g.a...
CVE-2024-47091HIGH7.8Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a l...
CVE-2026-41050CRITICAL9.9Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git pus...
CVE-2026-3004MEDIUM6.4The Snow Monkey Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-slick' attribute ...
CVE-2026-25705HIGH8.4A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-ra...
CVE-2025-14767MEDIUM5.5The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text...
CVE-2026-6965MEDIUM5.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere...
CVE-2026-6929HIGH7.5The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based blin...
CVE-2026-44612HIGH8.4Bytello Share (Windows Edition) installer executable provided by Bytello insecurely loads Dynamic Link Libraries. If the...
CVE-2026-32661CRITICAL9.8Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS ve...
CVE-2026-2725MEDIUM5.3Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated at...
CVE-2026-21024MEDIUM6.3Improper privilege management in Samsung System Support Service prior to version 8.0.8.0 allows local attackers to trigg...
CVE-2026-21022MEDIUM5.5Improper handling of insufficient permissions in Routines prior to SMR May-2026 Release 1 allows local attackers to acce...
CVE-2026-21021MEDIUM6.8Improper input validation in Routines prior to SMR May-2026 Release 1 allows physical attackers to launch privileged act...
CVE-2026-21020HIGH7.8Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to tri...
CVE-2026-21019HIGH8.6Improper input validation in FacAtFunction in Galaxy Watch prior to SMR May-2026 Release 1 allows local attacker to exec...
CVE-2026-21018MEDIUM6.7Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary...
CVE-2026-21016MEDIUM5.5Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensi...
CVE-2026-21015MEDIUM5.5Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique id...
CVE-2025-14033MEDIUM5.3The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a mi...
CVE-2025-11159HIGH7.2Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vul...
CVE-2026-7635HIGH8.1The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versi...
CVE-2026-7619MEDIUM6.5The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul...