CVE Vulnerability Database

Search and browse 377,710 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-16443CRITICAL9.1A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine ...
CVE-2026-15979HIGH8.1The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Del...
CVE-2025-70962HIGH7.5Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials ...
CVE-2026-71294HIGH7.6Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. ...
CVE-2026-71293MEDIUM6.2Statamic CMS's user-augmentation resolver, AugmentedUser::get in src/Auth/AugmentedUser.php, contains an explicit case f...
CVE-2026-71292HIGH7.2Subrion CMS's admin grid sorting helper, _gridGetSorting in includes/classes/ia.base.controller.admin.php, whitelists th...
CVE-2026-71291HIGH8.8Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registe...
CVE-2026-71289CRITICAL9.8The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publi...
CVE-2026-71288HIGH8.8Koha's guided report builder (reports/guided_reports.pl) reads the CGI parameter and, for each value, a dynamically-name...
CVE-2026-71287HIGH8.8Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . Because ...
CVE-2026-71286MEDIUM6.1The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its property...
CVE-2026-71285HIGH8.1Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo ...
CVE-2026-71284HIGH7.2Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), takes the fir...
CVE-2026-71283MEDIUM4.9Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), calls tarfile...
CVE-2026-71282MEDIUM6.5ChirpStack's SQLite-backend device tag filtering (chirpstack/src/storage/device.rs, in both get_count and list) interpol...
CVE-2026-71281HIGH8.8Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src...
CVE-2026-71280HIGH8.5go-shiori's DownloadBookmark (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Clien...
CVE-2026-71279HIGH8Zigbee2MQTT's ExternalJSExtension.getFilePath (lib/extension/externalJS.ts) joins a parameter received via an MQTT messa...
CVE-2026-71278CRITICAL9.8rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) cont...
CVE-2026-71277CRITICAL9.1rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP ...
CVE-2026-71276HIGH7.1Magistrala (formerly Mainflux)'s message-readers API reads a value from the HTTP query string (readers/api/http/transpor...
CVE-2026-71275MEDIUM5.4OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML r...
CVE-2026-71274HIGH8.5OpenBK7231T's CHANNEL_SetLabel (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel co...
CVE-2026-71273MEDIUM6.5OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request w...
CVE-2026-71272HIGH8.5Memos' webhook dispatch function safeDialContext (internal/webhook/webhook.go) resolves the target hostname via net.Defa...