CVE Vulnerability Database

Search and browse 380,713 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-18322HIGH8.8The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu...
CVE-2026-16143HIGH7.2The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2026-15941MEDIUM6.5The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches f...
CVE-2026-15918HIGH7.5VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of t...
CVE-2026-11421MEDIUM6.5The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Inje...
CVE-2026-18901HIGH7.3A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/e...
CVE-2026-18900HIGH7.3A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the co...
CVE-2026-18898HIGH8.8A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the fil...
CVE-2026-18907HIGH7.5Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via direc...
CVE-2026-18897HIGH8.8A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strc...
CVE-2026-18896MEDIUM6.3A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown fun...
CVE-2026-18895HIGH8.8A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /go...
CVE-2026-18859HIGH7.3A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/u...
CVE-2026-18856MEDIUM4.7A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFil...
CVE-2026-46334HIGH8.7OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a d...
CVE-2026-45809HIGH8.7OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a d...
CVE-2026-45705MEDIUM5.3OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the fin...
CVE-2026-18854HIGH7.3A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element ...
CVE-2026-18853MEDIUM5.3A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the fu...
CVE-2026-18852LOW3.3A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This imp...
CVE-2026-18103MEDIUM4.9A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Program...
CVE-2026-45537CRITICAL9.1OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the con...
CVE-2026-18819MEDIUM4.3A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vul...
CVE-2026-18818MEDIUM6.3A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView o...
CVE-2026-70620MEDIUM6.8Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attacke...