CVE Vulnerability Database

Search and browse 398,067 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-61310MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in the acc-menu_billings.php component of GmbH Mecury Managed Print ...
CVE-2025-61309MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_departments.php component of GmbH Mecury Managed Pri...
CVE-2025-61308MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_maintenance.php component of GmbH Mecury Managed Pri...
CVE-2025-61307MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in the acc-menu_papers.php component of GmbH Mecury Managed Print Se...
CVE-2025-61306MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_coveragealerts.php component of GmbH Mecury Managed ...
CVE-2025-61305MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_firmware.php component of GmbH Mecury Managed Print ...
CVE-2026-8290MEDIUM6.5A security flaw has been discovered in Open5GS up to 2.7.7. This issue affects the function smf_nsmf_handle_update_data_...
CVE-2026-8289MEDIUM6.5A vulnerability was identified in Open5GS up to 2.7.7. This vulnerability affects the function smf_nsmf_handle_update_da...
CVE-2026-4802HIGH8A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the h...
CVE-2026-8288MEDIUM6.5A vulnerability was determined in Open5GS up to 2.7.7. This affects the function gsm_handle_pdu_session_modification_qos...
CVE-2025-9973HIGH7.2Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server al...
CVE-2025-10470HIGH8.6The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or re...
CVE-2026-6956MEDIUM5.1ATutor is vulnerable to Reflected XSS in /install/install.php endpoint. An attacker can provide a specially crafted URL ...
CVE-2026-6909MEDIUM5.1ATutor is vulnerable to Reflected XSS in /install/upgrade.php endpoint. An attacker can provide a specially crafted URL ...
CVE-2026-41951HIGH8.6Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS te...
CVE-2026-40636HIGH7.8Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded c...
CVE-2026-35157CRITICAL9.8Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper neutraliz...
CVE-2026-32658HIGH8.8Dell Automation Platform versions prior to 2.0.0.0, contains a missing authorization vulnerability. A low privileged att...
CVE-2026-26946MEDIUM6.7Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper privilege...
CVE-2025-8325HIGH8.8The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/E...
CVE-2025-8154HIGH7.5In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient valida...
CVE-2025-43992MEDIUM5.6Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an authentication byp...
CVE-2025-10908HIGH7.3Due to a lack of user account state validation during authentication, locked user accounts can be successfully authentic...
CVE-2024-0391MEDIUM4.3The check user account lock states feature within the email OTP flow fails to validate user input, allowing an attacker ...
CVE-2026-43826MEDIUM6.5The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:pa...