CVE Vulnerability Database

Search and browse 377,709 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-48911HIGH7.5Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: throug...
CVE-2026-48834HIGH7.5Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: t...
CVE-2026-39924MEDIUM6.8Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid sess...
CVE-2026-39923CRITICAL9.2Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers t...
CVE-2026-32835Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-18531MEDIUM5.3IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use ...
CVE-2026-16442CRITICAL9.8A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authenti...
CVE-2026-15656MEDIUM4.3IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cook...
CVE-2026-15587CRITICAL9.4Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows...
CVE-2026-15572HIGH8.8A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mappe...
CVE-2026-13477HIGH8.8IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privilege...
CVE-2026-12762MEDIUM5.3IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensiti...
CVE-2026-12730LOW3.8IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 throug...
CVE-2026-10025CRITICAL9.8IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injec...
CVE-2026-54876HIGH7.5Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by...
CVE-2026-17613HIGH7.5Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated ...
CVE-2026-16102HIGH8.1A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solut...
CVE-2026-16100MEDIUM6.5A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error...
CVE-2026-16071MEDIUM5.4A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external direc...
CVE-2026-15573HIGH8.1A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security ...
CVE-2026-12410HIGH7.8Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-...
CVE-2026-7529HIGH7.5The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and...
CVE-2026-7456MEDIUM6.5The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2026-67623HIGH8.8Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary com...
CVE-2026-17506HIGH7.2The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tr...