CVE Vulnerability Database

Search and browse 398,150 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-29080HIGH8.8A SQL injection vulnerability in `FilterEngine.create_sqla_query()` allows any authenticated Rucio user to execute arbit...
CVE-2026-23870HIGH7.5A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpo...
CVE-2026-21661HIGH8.4An Uncontrolled Search Path Element vulnerability in JohnsonControls AC2000 on Windows allows Leveraging/Manipulating Co...
CVE-2026-20219MEDIUM5.4A vulnerability in the REST API of Cisco Slido could have allowed an authenticated, remote attacker to access the social...
CVE-2026-20195MEDIUM5.3A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker to e...
CVE-2026-20193MEDIUM4.3A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker with ...
CVE-2026-20189MEDIUM4.3A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an authenticated, ...
CVE-2026-20188NONE0Following the initial publication of the Security Advisory about a denial of service (DoS) condition in Cisco Crosswork ...
CVE-2026-20185HIGH7.7A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco 350 Series Managed Switches (SG...
CVE-2026-20172MEDIUM4.3A vulnerability in the Lite Agent feature of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote ...
CVE-2026-20169MEDIUM6.4A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, ...
CVE-2026-20168MEDIUM6.5A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, ...
CVE-2026-20167HIGH7.7A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, ...
CVE-2026-20035HIGH7.2A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to con...
CVE-2026-20034HIGH8.8A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote att...
CVE-2026-6863MEDIUM6.8Velociraptor versions prior to 0.76.4 contain a cross organization authorization bypass in the HTTP API. A user with onl...
CVE-2026-6788HIGH7.8Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows allows Using Malicious Files.
CVE-2026-6787HIGH7.8Use of Hard-coded Cryptographic Key vulnerability in WatchGuard Agent on Windows allows Inclusion of Code in Existing Pr...
CVE-2026-6691HIGH8.6The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling ...
CVE-2026-41288HIGH7.8Incorrect permission assignment for a resource in the patch management component of the WatchGuard Agent on Windows allo...
CVE-2026-41286MEDIUM6.5Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. ...
CVE-2026-8028LOW3.7A vulnerability was detected in FlowiseAI Flowise up to 3.0.12. This affects the function verify of the file packages/se...
CVE-2026-8027MEDIUM5.3A weakness has been identified in FlowiseAI Flowise up to 3.0.12. Affected by this vulnerability is an unknown functiona...
CVE-2026-41287MEDIUM6.5Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. ...
CVE-2025-52613HIGH8.8HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated ...