CVE Vulnerability Database

Search and browse 398,007 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-15463MEDIUM6.5The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all vers...
CVE-2026-8449——Rejected reason: This CVE ID has been rejected or withdrawn.
CVE-2026-45227HIGH8.8Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that allows authenticated ...
CVE-2026-45226HIGH7.6Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users ...
CVE-2026-45225HIGH7.6Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users t...
CVE-2026-44871HIGH8.8Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS...
CVE-2026-44307HIGH8.7Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\...
CVE-2026-44306MEDIUM5.3Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.21 and 6.15.0, responses from the f...
CVE-2026-44305MEDIUM6.8Lemur manages TLS certificate creation. Prior to 1.9.0, when LDAP TLS is enabled (LDAP_USE_TLS = True), Lemur's LDAP aut...
CVE-2026-44304HIGH8.1Lemur manages TLS certificate creation. Prior to 1.9.0, Lemur's LDAP authentication module (lemur/auth/ldap.py) construc...
CVE-2026-44302HIGH7.5Snappier is a high performance C# implementation of the Snappy compression algorithm. Prior to 1.3.1, Snappier.SnappyStr...
CVE-2026-44301HIGH8.1Hugo is a static site generator. From 0.43 to before 0.161.0, when building a Hugo site that uses Node-based asset pipel...
CVE-2026-44296HIGH7.5Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vul...
CVE-2026-44262CRITICAL9.4Scramble generates API documentation for Laravel project. From 0.13.2 to before 0.13.22, when documentation endpoints ar...
CVE-2026-44260HIGH8.1efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is int...
CVE-2026-44259MEDIUM4.6efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the previewServlet serves files with their detected MIME t...
CVE-2026-44258CRITICAL9.3efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the elfinder_checkRisk function validates target and targe...
CVE-2026-44257CRITICAL9.3efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManager.unZip writes zip entries to disk usin...
CVE-2026-44242LOW3.7Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applicat...
CVE-2026-44241HIGH7.5Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applicat...
CVE-2026-44015CRITICAL9.9Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Serve...
CVE-2026-43948CRITICAL9.9wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_...
CVE-2026-42855HIGH7.5arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Pr...
CVE-2026-42854CRITICAL9.8arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Pr...
CVE-2026-42844HIGH8.8Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write ca...