CVE Vulnerability Database

Search and browse 398,130 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-41491HIGH8.1Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. From versions 1.3...
CVE-2026-41423MEDIUM5.3Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-41161MEDIUM5.3Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version...
CVE-2026-39816HIGH8.8The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Requi...
CVE-2026-32803LOW3.3Dell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.10.1.5 and 9.11.0.0 ...
CVE-2025-71302MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/panthor: fix for dma-fence safe access rules C...
CVE-2025-71301MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around vmap...
CVE-2025-71300MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Revert "arm64: zynqmp: Add an OP-TEE node to the de...
CVE-2025-71299MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Parse DT for flashes with the...
CVE-2025-71298MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around madv...
CVE-2025-71297MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: 8822b: Avoid WARNING in rtw8822b_confi...
CVE-2025-71296MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around purg...
CVE-2026-8077HIGH8.6Lack of proper authorization implementation in the CashDro 3 web administration panel, version 24.01.00.26. The backend ...
CVE-2026-25199CRITICAL9.1Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This...
CVE-2026-25077HIGH8.8Account users are allowed by default to register templates to be downloaded directly to the primary storage for deployin...
CVE-2025-69233MEDIUM5.3Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as mi...
CVE-2025-66467HIGH8.1Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which the...
CVE-2025-66172HIGH8.1The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated u...
CVE-2025-66171MEDIUM6.5The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated u...
CVE-2025-66170MEDIUM6.5The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenti...
CVE-2022-50994CRITICAL9.2DrayTek Vigor 2960 firmware versions prior to 1.5.1.4 contain an OS command injection vulnerability in the CGI login han...
CVE-2026-8153CRITICAL9.8OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows unauthe...
CVE-2026-8076CRITICAL9.3Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of nu...
CVE-2026-3318MEDIUM5.3Open redirection vulnerability in the latest demo version of the Cradle eCommerce platform. The vulnerability occurs in ...
CVE-2026-7650MEDIUM6.4The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id'...