CVE Vulnerability Database

Search and browse 381,192 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-34497MEDIUM5.4Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Syste...
CVE-2026-34495MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls F...
CVE-2026-34490MEDIUM5.5Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attac...
CVE-2026-21662CRITICAL9.8Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malic...
CVE-2026-67822CRITICAL9.8Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The fu...
CVE-2026-58048CRITICAL9.4Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
CVE-2026-58047MEDIUM5.6HTTP Smuggling in cPanel allows potential leak of credentials.
CVE-2026-54707MEDIUM5.4OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien...
CVE-2026-54706MEDIUM4.8OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien...
CVE-2026-52856HIGH7.5Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a ...
CVE-2026-52855CRITICAL9.9Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{...
CVE-2026-67607HIGH8.2LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thr...
CVE-2026-59232MEDIUM5.3Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding ...
CVE-2026-59231MEDIUM5.3Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to...
CVE-2026-56571MEDIUM5.3HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions...
CVE-2026-56570MEDIUM5.3HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Va...
CVE-2026-56569LOW3.3HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal config...
CVE-2026-56568MEDIUM5.3HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It inv...
CVE-2026-56567LOW3.3HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of intern...
CVE-2026-52857MEDIUM5.5Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, un...
CVE-2026-18141HIGH8.2A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthentic...
CVE-2026-17566CRITICAL9.9pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query in...
CVE-2026-17351CRITICAL9The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_qu...
CVE-2026-17350MEDIUM5.4The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce...
CVE-2026-17349CRITICAL9.6/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of ...