CVE Vulnerability Database

Search and browse 378,068 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-18613CRITICAL9.8A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of t...
CVE-2026-18612CRITICAL9.8A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/p...
CVE-2025-9291MEDIUM6.5A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certif...
CVE-2026-69153MEDIUM5.3PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract ...
CVE-2026-69152HIGH7.5The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3...
CVE-2026-69151MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-69149MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-68945MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-68930MEDIUM6.5Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for reci...
CVE-2026-68869Rejected reason: This CVE ID was assigned in error. Upon further review, the reported issue does not represent a securit...
CVE-2026-67612MEDIUM4.8OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that al...
CVE-2026-67611HIGH8.6OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to ci...
CVE-2026-67610HIGH8.1OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoi...
CVE-2026-61372HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. Thi...
CVE-2026-41453HIGH8.8Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated use...
CVE-2026-41452CRITICAL9.8Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated...
CVE-2026-39932CRITICAL9.1OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/cl...
CVE-2026-39931HIGH8.6OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature t...
CVE-2026-18718HIGH7.1Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to exe...
CVE-2026-18610MEDIUM5.5A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP_Com_FileList.asp...
CVE-2026-18607HIGH8.8A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN53...
CVE-2026-18606HIGH7.8A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown function...
CVE-2026-18605HIGH7A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown function in the library A...
CVE-2026-18604MEDIUM5.3A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function D...
CVE-2026-18602CRITICAL9.8A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_conf...