CVE Vulnerability Database

Search and browse 380,957 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-67611HIGH8.6OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to ci...
CVE-2026-67610HIGH8.1OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoi...
CVE-2026-61372HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. Thi...
CVE-2026-41453HIGH8.8Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated use...
CVE-2026-41452CRITICAL9.8Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated...
CVE-2026-39932CRITICAL9.1OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/cl...
CVE-2026-39931HIGH8.6OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature t...
CVE-2026-18718HIGH7.1Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to exe...
CVE-2026-18610MEDIUM5.5A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP_Com_FileList.asp...
CVE-2026-18607HIGH8.8A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN53...
CVE-2026-18606HIGH7.8A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown function...
CVE-2026-18605HIGH7A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown function in the library A...
CVE-2026-18604MEDIUM5.3A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function D...
CVE-2026-18602CRITICAL9.8A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_conf...
CVE-2026-18477MEDIUM4.4A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local a...
CVE-2026-18243MEDIUM6.9Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticat...
CVE-2026-18651MEDIUM5.4A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind cr...
CVE-2026-18568HIGH7.5XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when ev...
CVE-2026-18508MEDIUM4.4A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confin...
CVE-2026-18248CRITICAL9.1@fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.cont...
CVE-2026-15430MEDIUM6.2Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, ...
CVE-2026-67609HIGH8.5Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalatio...
CVE-2026-9487CRITICAL9.1XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, ...
CVE-2026-9390CRITICAL9.1XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Si...
CVE-2026-69097HIGH7.3GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitra...