CVE Vulnerability Database

Search and browse 381,202 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-15227MEDIUM5.3Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking t...
CVE-2026-46594MEDIUM5.1A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicio...
CVE-2026-46593HIGH8.6A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input...
CVE-2025-67651MEDIUM6.9A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF ...
CVE-2025-67650HIGH8.6An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralizatio...
CVE-2025-67649CRITICAL9.3A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input ...
CVE-2026-64607MEDIUM5.3HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection ma...
CVE-2026-62391HIGH8.1The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend...
CVE-2026-44615MEDIUM6.5Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker wi...
CVE-2026-17567MEDIUM5.3The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne...
CVE-2026-16843HIGH7.2Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validatio...
CVE-2026-18437MEDIUM5.3The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access ...
CVE-2026-18436MEDIUM5.3The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the ...
CVE-2026-15722HIGH7.5A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function ...
CVE-2026-11770HIGH7.5A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the Cle...
CVE-2026-10079HIGH8.5A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, AC...
CVE-2026-65313HIGH8.1A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-c...
CVE-2026-65311MEDIUM5.3The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoi...
CVE-2026-65310HIGH7.5ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configu...
CVE-2026-65309HIGH7.5ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible form...
CVE-2026-18218MEDIUM5.4A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attemp...
CVE-2026-18217MEDIUM4.7A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution...
CVE-2026-18215HIGH8.1Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization...
CVE-2026-18214HIGH8.1Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Wor...
CVE-2026-18211MEDIUM5.4A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is respo...