CVE Vulnerability Database

Search and browse 398,007 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-8431HIGH7.2An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggeri...
CVE-2026-8430CRITICAL9.2SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certa...
CVE-2026-8429HIGH8.8SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers t...
CVE-2026-34684HIGH7.8Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could resul...
CVE-2026-34683HIGH7.8Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could resul...
CVE-2026-34682HIGH7.8Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could resul...
CVE-2026-34681HIGH7.8Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could resul...
CVE-2026-34664MEDIUM6.3Substance3D - Designer versions 15.1.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted ...
CVE-2026-34660CRITICAL9.3Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that c...
CVE-2026-34659CRITICAL9.6Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerabili...
CVE-2026-23823HIGH7.2A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attack...
CVE-2026-23822MEDIUM5.3A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to t...
CVE-2026-23821HIGH7.2A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remot...
CVE-2026-23820HIGH7.2A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authentic...
CVE-2026-23819HIGH8.8A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an u...
CVE-2026-5146MEDIUM4.3Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacke...
CVE-2026-44343CRITICAL9.8WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard t...
CVE-2026-44279MEDIUM5.5An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, Forti...
CVE-2026-44278MEDIUM5.5A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindo...
CVE-2026-44277CRITICAL9.8A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticat...
CVE-2026-44204MEDIUM6.5Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortB...
CVE-2026-44196CRITICAL9.1Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication...
CVE-2026-44184HIGH8Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download c...
CVE-2026-44183CRITICAL9.8Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download c...
CVE-2026-44167HIGH7.5phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 fil...