CVE Vulnerability Database

Search and browse 378,068 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-18477MEDIUM4.4A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local a...
CVE-2026-18243MEDIUM6.9Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticat...
CVE-2026-18651MEDIUM5.4A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind cr...
CVE-2026-18568HIGH7.5XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when ev...
CVE-2026-18508MEDIUM4.4A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confin...
CVE-2026-18248CRITICAL9.1@fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.cont...
CVE-2026-15430MEDIUM6.2Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, ...
CVE-2026-67609HIGH8.5Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalatio...
CVE-2026-9487CRITICAL9.1XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, ...
CVE-2026-9390CRITICAL9.1XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Si...
CVE-2026-69097HIGH7.3GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitra...
CVE-2026-69096HIGH8.8OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after...
CVE-2026-69095HIGH8.7OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in ...
CVE-2026-69094MEDIUM5.3Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_fu...
CVE-2026-69093HIGH7.1Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs pe...
CVE-2026-69092MEDIUM6.9Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echo...
CVE-2026-69091HIGH8.7Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only ...
CVE-2026-69090MEDIUM6.9Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role adm...
CVE-2026-69089HIGH8.7Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image...
CVE-2026-69088HIGH8.6Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint...
CVE-2026-69087HIGH7.1The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, th...
CVE-2026-69086HIGH8.3SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints,...
CVE-2026-69085CRITICAL10SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-s...
CVE-2026-69084CRITICAL10SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement...
CVE-2026-69083CRITICAL10SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable...