CVE Vulnerability Database

Search and browse 398,143 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-40004HIGH7.8There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execut...
CVE-2026-4807MEDIUM6.5The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and inclu...
CVE-2026-44600MEDIUM5.3Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-202...
CVE-2026-44599MEDIUM5.3Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.
CVE-2026-6222MEDIUM5.3The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1....
CVE-2026-40003MEDIUM6.8ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the l...
CVE-2026-44597CRITICAL9.1Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload,...
CVE-2026-6278——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-41484MEDIUM5.9OpenTelemetry.Exporter.OneCollector is a .NET exporter that sends telemetry to a OneCollector back-end over HTTP. In ver...
CVE-2026-41483MEDIUM5.9OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlie...
CVE-2026-41417MEDIUM5.3Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created f...
CVE-2026-41310MEDIUM5.3OpenTelemetry.Exporter.Zipkin is the .NET Zipkin exporter for OpenTelemetry. In versions 1.15.2 and earlier, the Zipkin ...
CVE-2026-40296MEDIUM5.4PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The HTML writer skips htmlspecialchars e...
CVE-2026-3291MEDIUM5.5Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated vers...
CVE-2026-40332MEDIUM5.3Masa CMS is affected by an Open Redirect vulnerability due to improper handling of scheme-relative URLs. The application...
CVE-2026-40281CRITICAL9.1Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint v...
CVE-2026-40251MEDIUM6.5Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora...
CVE-2026-40243MEDIUM4.8Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OV...
CVE-2026-40197MEDIUM6.5Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora...
CVE-2026-40195MEDIUM6.5Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora...
CVE-2026-8033MEDIUM5.5A vulnerability has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. This affects an unknown function of t...
CVE-2026-8032HIGH7.3A flaw has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. The impacted element is an unknown function of...
CVE-2026-44118HIGH8.5OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request heade...
CVE-2026-44117MEDIUM6.3OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips U...
CVE-2026-44116HIGH8.6OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function t...