CVE Vulnerability Database

Search and browse 379,600 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-71262CRITICAL9.8IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (...
CVE-2026-71261HIGH7.8dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk metadata parsing. I...
CVE-2026-71260MEDIUM6.5ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (espho...
CVE-2026-71259HIGH8.6ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py...
CVE-2026-71227MEDIUM5.1A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO...
CVE-2026-71226HIGH7.3Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all subm...
CVE-2026-71225MEDIUM6.5A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stat...
CVE-2026-16022HIGH7.8@oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constr...
CVE-2026-0516MEDIUM6.5A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to...
CVE-2026-71256CRITICAL9.8nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_iden...
CVE-2026-71255HIGH8.6nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identification_res...
CVE-2026-71254CRITICAL9.8nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (F...
CVE-2026-64582HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap ...
CVE-2026-61891HIGH7.5In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoin...
CVE-2026-46581HIGH7.5In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or ...
CVE-2026-18933HIGH7.2The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-pri...
CVE-2026-71252HIGH8.2toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands, ...
CVE-2026-71251MEDIUM6.5Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download...
CVE-2026-71250MEDIUM4.3Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters most private/reserved IPv4 ranges but contains an ex...
CVE-2026-71249MEDIUM6.1299Ko's public contact form (plugin/contact/controllers/ContactController.php, home) sets raw POST field values (name, f...
CVE-2026-71248CRITICAL9.8Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw P...
CVE-2026-71247MEDIUM6.5Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role t...
CVE-2026-71246MEDIUM4.3Pixelfed's SearchController (behind the auth middleware) accepts a URL via its remote-search parameters and fetches it s...
CVE-2026-71245Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.
CVE-2026-71244MEDIUM6.5Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, r...