CVE Vulnerability Database

Search and browse 398,143 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-2514MEDIUM5.3Improper restriction of excessive authentication attempts vulnerability in Hitachi Virtual Storage Platform G130, G150, ...
CVE-2025-1978CRITICAL9.8Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage ...
CVE-2024-43384HIGH8A low privileged remote attacker can gain the root password due to improper removal of sensitive information before stor...
CVE-2026-4430HIGH7.8Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched enc...
CVE-2026-44406HIGH7.8ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM...
CVE-2025-9661CRITICAL9.8OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One B...
CVE-2026-8063HIGH7.1An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When ...
CVE-2026-7252HIGH8.1The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress...
CVE-2026-6692HIGH8.8The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_...
CVE-2026-4348HIGH7.5The BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the `get_current_letter_docs` and `docs_sort_...
CVE-2026-41641HIGH7.2NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t...
CVE-2026-41586CRITICAL9.8Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applica...
CVE-2026-41413HIGH7.7Istio is an open platform to connect, manage, and secure microservices. Prior to versions 1.28.6 and 1.29.2, when a Requ...
CVE-2026-41143HIGH8.8YesWiki is a wiki system written in PHP. Prior to version 4.6.1, YesWiki bazar module contains a SQL injection vulnerabi...
CVE-2026-41139HIGH8.8Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary...
CVE-2026-6214MEDIUM6.5The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0....
CVE-2026-44603CRITICAL9.1Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.
CVE-2026-44602HIGH7.5Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006.
CVE-2026-44601HIGH7.5Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close o...
CVE-2026-42217CRITICAL9.8OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-42216CRITICAL9.1OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-42194MEDIUM6.8Admidio is an open-source user management solution. Prior to version 5.0.9, the incomplete SSRF fix in Admidio's fetch_m...
CVE-2026-41891MEDIUM5.3CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-41890MEDIUM6.9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-41675HIGH7.5xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom...