CVE Vulnerability Database

Search and browse 378,055 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-14848MEDIUM5.4The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified th...
CVE-2026-14824MEDIUM4.8The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outp...
CVE-2026-14816MEDIUM6.5The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of th...
CVE-2026-12698MEDIUM4.3The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing thei...
CVE-2026-11366LOW3.7The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthentica...
CVE-2026-10526MEDIUM5.8The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests th...
CVE-2026-68744LOW3.3A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for...
CVE-2026-18739LOW2.5A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when...
CVE-2026-18569LOW3.7A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Bui...
CVE-2026-16881HIGH8.7A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component...
CVE-2026-42169HIGH7.3A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `f...
CVE-2026-18723MEDIUM6.3A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file...
CVE-2026-18722MEDIUM6.3A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurv...
CVE-2026-18721MEDIUM4.3A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown processing of the file...
CVE-2026-14818HIGH7.2A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versi...
CVE-2026-8508MEDIUM6.5An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions throug...
CVE-2026-6837HIGH7.2A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions...
CVE-2026-18720MEDIUM5.5A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?...
CVE-2026-18719MEDIUM6.3A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2html.py of the compo...
CVE-2026-58045MEDIUM6.2A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:z...
CVE-2026-58044LOW3.7A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild ou...
CVE-2026-58042MEDIUM5.9A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Rec...
CVE-2026-58041MEDIUM5.3A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to cont...
CVE-2026-56846HIGH7.5A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memor...
CVE-2026-56845HIGH7.5An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configur...