CVE Vulnerability Database

Search and browse 378,452 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-69091HIGH8.7Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only ...
CVE-2026-69090MEDIUM6.9Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role adm...
CVE-2026-69089HIGH8.7Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image...
CVE-2026-69088HIGH8.6Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint...
CVE-2026-69087HIGH7.1The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, th...
CVE-2026-69086HIGH8.3SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints,...
CVE-2026-69085CRITICAL10SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-s...
CVE-2026-69084CRITICAL10SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement...
CVE-2026-69083CRITICAL10SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable...
CVE-2026-68587CRITICAL9.2SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHea...
CVE-2026-68586CRITICAL9.2SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints...
CVE-2026-68585MEDIUM6.9SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that r...
CVE-2026-68584CRITICAL9.2SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning end...
CVE-2026-67608HIGH8.6Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injecti...
CVE-2026-64827CRITICAL9.8Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication byp...
CVE-2026-18642HIGH7.8Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock ...
CVE-2026-18601CRITICAL9.8A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the fi...
CVE-2026-18600HIGH8.8A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.s...
CVE-2026-18108CRITICAL9.8Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an Encr...
CVE-2026-18092HIGH8.1Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xm...
CVE-2026-18089HIGH7.5Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-em...
CVE-2026-56609MEDIUM6.5HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using...
CVE-2026-56608MEDIUM5.3HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular acce...
CVE-2026-2346CRITICAL9.8Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integ...
CVE-2026-18599HIGH8A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the f...