CVE Vulnerability Database

Search and browse 398,366 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-6344MEDIUM4.9The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This i...
CVE-2026-35254MEDIUM6.1Vulnerability in the Oracle OCI CLI product of Oracle Open Source Projects. The supported versions that is affected is 3...
CVE-2026-35253MEDIUM4.7Vulnerability in the Oracle Macoron Tool product of Oracle Open Source Projects. The supported versions that is affected...
CVE-2026-23928MEDIUM6.8The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when H...
CVE-2026-23927MEDIUM6.5A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead ...
CVE-2026-23926MEDIUM6.8An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by...
CVE-2026-2306MEDIUM4.3The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation du...
CVE-2026-5753MEDIUM6.5The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions ...
CVE-2026-3208MEDIUM5.3The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a mis...
CVE-2026-7573HIGH7.7An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 a...
CVE-2026-7572MEDIUM5.5An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor befor...
CVE-2025-71256HIGH7.5In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no addition...
CVE-2025-71255HIGH7.5In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additio...
CVE-2025-71254HIGH7.5In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additio...
CVE-2025-71253HIGH7.5In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additio...
CVE-2025-71252HIGH7.5In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additio...
CVE-2025-71251HIGH7.5In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service w...
CVE-2026-44405LOW3.4In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.
CVE-2026-40934MEDIUM6.8Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign auth...
CVE-2026-40110HIGH7.3Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation...
CVE-2026-40075HIGH7.5OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8...
CVE-2026-28780CRITICAL9.8Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a maliciou...
CVE-2026-41950MEDIUM6.5Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the fu...
CVE-2026-40068HIGH8.8In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir f...
CVE-2026-39852HIGH8.2Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3...