CVE Vulnerability Database

Search and browse 380,829 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-15314HIGH7.5Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HT...
CVE-2026-15307HIGH8.8An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse...
CVE-2025-29296CRITICAL9.8H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V...
CVE-2026-69254CRITICAL9.4Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScri...
CVE-2026-69253CRITICAL9Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1...
CVE-2026-69252HIGH7.2Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/fil...
CVE-2026-69110CRITICAL9.3OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attacker...
CVE-2026-69100HIGH8.8LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability i...
CVE-2026-69098CRITICAL9.8kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows ...
CVE-2026-25292HIGH7.6Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration...
CVE-2026-25289CRITICAL9.6Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with inv...
CVE-2026-25288HIGH7.4Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
CVE-2026-24084HIGH7.5Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed cap...
CVE-2026-24083HIGH7.8Memory Corruption while processing IOCTL device driver requests with invalid arguments.
CVE-2026-24080HIGH7.8Memory Corruption when handling malformed request parameters in the fingerprint TA.
CVE-2026-24079HIGH8.1Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
CVE-2026-24078MEDIUM6.5Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
CVE-2026-24077MEDIUM6.5Information Disclosure when processing wireless network channel switch information with improperly formatted length fiel...
CVE-2026-24076MEDIUM6.7Memory Corruption when processing registry values with incorrect types using a direct query method.
CVE-2026-21366HIGH7.8Memory corruption while processing a packet with a size close to the maximum allowed value.
CVE-2026-18801CRITICAL9.3OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution ...
CVE-2026-18773MEDIUM6.3A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_...
CVE-2026-10032MEDIUM6.1The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the U...
CVE-2026-69251CRITICAL9Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record ...
CVE-2026-69250HIGH8.5Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 toke...