CVE Vulnerability Database

Search and browse 379,600 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-71243HIGH8.8The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, dest...
CVE-2026-71242HIGH8.3Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership ...
CVE-2026-71241HIGH7.5Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are mi...
CVE-2026-71240MEDIUM4.3DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or sta...
CVE-2026-71239HIGH8.1DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template const...
CVE-2026-71238CRITICAL9.1DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from ...
CVE-2026-71237CRITICAL9.8Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sa...
CVE-2026-71236HIGH8.7Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incomi...
CVE-2026-71235HIGH8.8Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-sid...
CVE-2026-71234HIGH7.5Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPubl...
CVE-2026-71233HIGH8.7InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output...
CVE-2026-71232HIGH7.2MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template ...
CVE-2026-71231CRITICAL9.8IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decod...
CVE-2026-66747CRITICAL9.8Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across ...
CVE-2026-60009HIGH8.8In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every...
CVE-2026-17578LOW2.3Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D re...
CVE-2026-14574MEDIUM6.5In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` rec...
CVE-2026-14304MEDIUM5.5In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and...
CVE-2026-12609HIGH7.5In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlug...
CVE-2026-44945CRITICAL9.1A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An...
CVE-2026-25703HIGH7.3NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authenticatio...
CVE-2026-15452MEDIUM4.7The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-Sit...
CVE-2026-0931MEDIUM6.9Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cau...
CVE-2026-8029LOW3.9The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements ...
CVE-2026-10090CRITICAL9A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cl...