CVE Vulnerability Database

Search and browse 378,409 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-18108CRITICAL9.8Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an Encr...
CVE-2026-18092HIGH8.1Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xm...
CVE-2026-18089HIGH7.5Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-em...
CVE-2026-56609MEDIUM6.5HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using...
CVE-2026-56608MEDIUM5.3HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular acce...
CVE-2026-2346CRITICAL9.8Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integ...
CVE-2026-18599HIGH8A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the f...
CVE-2026-18598HIGH8.8A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_l...
CVE-2026-18574CRITICAL9.3An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Se...
CVE-2026-69082HIGH8.8CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. Th...
CVE-2026-69079HIGH8.7CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endp...
CVE-2026-69078HIGH8.8CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functio...
CVE-2026-68742MEDIUM5.5A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen ...
CVE-2026-33591CRITICAL10A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security r...
CVE-2026-0392HIGH7.3eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is ...
CVE-2026-69075MEDIUM6.9FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-c...
CVE-2026-63563MEDIUM6.9Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication ...
CVE-2026-63545LOW2.4Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They...
CVE-2026-62416MEDIUM6.9Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, requir...
CVE-2026-60011MEDIUM6.9Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image...
CVE-2026-8794MEDIUM6.9PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote atta...
CVE-2026-8793MEDIUM6.9PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticat...
CVE-2026-28147MEDIUM5.4Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templa...
CVE-2026-21555HIGH7.5In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional ...
CVE-2026-21554HIGH7.5In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional ...