CVE Vulnerability Database

Search and browse 398,007 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-8053HIGH8.8An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write priv...
CVE-2026-6888HIGH7.2Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitr...
CVE-2025-62627HIGH7.2An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged ...
CVE-2025-62624HIGH8.8A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege esca...
CVE-2025-62623HIGH8.8A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege esca...
CVE-2025-61972HIGH8.5Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Ma...
CVE-2025-61971MEDIUM5.9Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to modify MMIO routing conf...
CVE-2024-36315MEDIUM5.7Improper enforcement of the LFENCE serialization property may allow an attacker to bypass speculation barriers and poten...
CVE-2026-8108HIGH7.8The installation of Fuji Tellus adds a driver to the kernel which grants all users read and write permissions.
CVE-2026-5371HIGH7.1The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnera...
CVE-2026-44548HIGH8.1ChurchCRM is an open-source church management system. Prior to 7.3.2, top-level cross-site GET navigation from an attack...
CVE-2026-44547CRITICAL9.6ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The ...
CVE-2026-44352MEDIUM5.3Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri...
CVE-2026-44347MEDIUM6.5Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.23.3, the SSO flow does not validate ...
CVE-2026-44341MEDIUM5.3GoJobs is a REST API for a Job Board platform. The application exposes a job retrieval endpoint that allows unauthentica...
CVE-2026-44245MEDIUM6.1Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 2.5.2, Vue 3's v-html directiv...
CVE-2026-43685HIGH7.2A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject a...
CVE-2026-43680HIGH7.2A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a...
CVE-2026-42289HIGH8.8ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and...
CVE-2026-42288CRITICAL10ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-...
CVE-2026-42158LOW2.3Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri...
CVE-2026-42157MEDIUM5.1Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri...
CVE-2026-42156HIGH7.1Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri...
CVE-2026-41901CRITICAL9Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security ...
CVE-2026-1250HIGH7.5The Court Reservation – Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection vi...