CVE Vulnerability Database

Search and browse 378,063 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-18685CRITICAL9.8A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the...
CVE-2026-11836LOW1.8Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in...
CVE-2026-11835MEDIUM5.6Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateRese...
CVE-2026-67978HIGH7.5An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmittin...
CVE-2026-67673MEDIUM4.6A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is...
CVE-2026-48399HIGH7.5Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a...
CVE-2026-48333CRITICAL9.8Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege esca...
CVE-2026-48331CRITICAL10Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in priv...
CVE-2026-48330CRITICAL10Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL ...
CVE-2026-48326CRITICAL9.9Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL ...
CVE-2026-48323CRITICAL10Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vul...
CVE-2026-48317CRITICAL9.6Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eva...
CVE-2026-18684CRITICAL9.8A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the f...
CVE-2026-18667CRITICAL9.6A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an...
CVE-2026-69249HIGH8.7python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to ...
CVE-2026-69248MEDIUM6.9cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0,...
CVE-2026-69247HIGH8.2cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 unti...
CVE-2026-67977HIGH7.5An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause...
CVE-2026-67975HIGH7.5Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new s...
CVE-2026-67974HIGH7.5A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7...
CVE-2026-67973HIGH7.5An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying f...
CVE-2026-67970HIGH7.5Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive co...
CVE-2026-67969HIGH7.5An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset v...
CVE-2026-67617MEDIUM4.8Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that al...
CVE-2026-67616MEDIUM5.3Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoi...