CVE Vulnerability Database

Search and browse 398,382 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-66369HIGH7.5An issue was discovered in MM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 128...
CVE-2025-61669MEDIUM6.1Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query pa...
CVE-2025-52206MEDIUM4.7ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage.
CVE-2026-7834CRITICAL9.8A security vulnerability has been detected in EFM ipTIME NAS1dual 1.5.24. This issue affects the function get_csrf_white...
CVE-2026-7778MEDIUM5An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has b...
CVE-2026-4304HIGH7.5The WeePie Cookie Allow plugin for WordPress is vulnerable to SQL Injection via the 'consent' parameter in all versions ...
CVE-2026-36356CRITICAL9.1The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthentica...
CVE-2026-36355HIGH7.7The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perfo...
CVE-2026-34408CRITICAL9.1An issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0). The password reset f...
CVE-2026-29168HIGH7.3Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response dat...
CVE-2026-7833HIGH7.3A weakness has been identified in EFM ipTIME C200 up to 1.092. This vulnerability affects the function sub_408F90 of the...
CVE-2026-7832HIGH7A security flaw has been discovered in IObit Advanced SystemCare 19. This affects an unknown part of the file ASC.exe of...
CVE-2026-6918HIGH7.5In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte c...
CVE-2026-30246MEDIUM6.5Fiber is a web framework for Go. In github.com/gofiber/fiber/v3 versions through 3.1.0, the default key generator in the...
CVE-2026-28510MEDIUM5.9eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably pr...
CVE-2026-27694MEDIUM5.4Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the ema...
CVE-2026-27693MEDIUM5.4Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML...
CVE-2026-27644MEDIUM6.5Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality write...
CVE-2026-6262MEDIUM6.5The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is...
CVE-2026-6261HIGH8.8The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is d...
CVE-2026-43574MEDIUM6.5OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolve...
CVE-2026-43573HIGH7.7OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser...
CVE-2026-43572MEDIUM6.3OpenClaw versions 2026.4.10 before 2026.4.14 contain a missing authorization vulnerability in the Microsoft Teams SSO in...
CVE-2026-43571HIGH8.8OpenClaw before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog lookups to reso...
CVE-2026-43570MEDIUM6.5OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository p...