CVE Vulnerability Database

Search and browse 379,570 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-54876HIGH7.5Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by...
CVE-2026-17613HIGH7.5Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated ...
CVE-2026-16102HIGH8.1A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solut...
CVE-2026-16100MEDIUM6.5A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error...
CVE-2026-16071MEDIUM5.4A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external direc...
CVE-2026-15573HIGH8.1A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security ...
CVE-2026-12410HIGH7.8Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-...
CVE-2026-7529HIGH7.5The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and...
CVE-2026-7456MEDIUM6.5The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2026-67623HIGH8.8Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary com...
CVE-2026-17506HIGH7.2The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tr...
CVE-2026-16443CRITICAL9.1A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine ...
CVE-2026-15979HIGH8.1The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Del...
CVE-2025-70962HIGH7.5Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials ...
CVE-2026-71294HIGH7.6Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. ...
CVE-2026-71293MEDIUM6.2Statamic CMS's user-augmentation resolver, AugmentedUser::get in src/Auth/AugmentedUser.php, contains an explicit case f...
CVE-2026-71292HIGH7.2Subrion CMS's admin grid sorting helper, _gridGetSorting in includes/classes/ia.base.controller.admin.php, whitelists th...
CVE-2026-71291HIGH8.8Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registe...
CVE-2026-71289CRITICAL9.8The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publi...
CVE-2026-71288HIGH8.8Koha's guided report builder (reports/guided_reports.pl) reads the CGI parameter and, for each value, a dynamically-name...
CVE-2026-71287HIGH8.8Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . Because ...
CVE-2026-71286MEDIUM6.1The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its property...
CVE-2026-71285HIGH8.1Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo ...
CVE-2026-71284HIGH7.2Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), takes the fir...
CVE-2026-71283MEDIUM4.9Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), calls tarfile...