CVE Vulnerability Database

Search and browse 375,912 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-67179HIGH7.8Genkit does not properly validate host request headers. Any host on the developer's network, and any website the develop...
CVE-2026-56721HIGH8.8CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference...
CVE-2026-56720MEDIUM5.3CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin users controller that ...
CVE-2026-53416HIGH7.1Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via loca...
CVE-2026-53415HIGH8.3Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code executio...
CVE-2026-53414MEDIUM6.5Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting partic...
CVE-2026-53413HIGH8.3Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting parti...
CVE-2026-48766HIGH7.6TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to exfiltr...
CVE-2026-48495HIGH7.1TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JS...
CVE-2026-42142HIGH7.1TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getShee...
CVE-2026-19546HIGH8.8A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed S...
CVE-2026-19078MEDIUM4.3A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the...
CVE-2026-18640HIGH7.1The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT perm...
CVE-2026-18639HIGH7.3When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, s...
CVE-2026-18638MEDIUM6.5Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server proces...
CVE-2026-14180MEDIUM5.3A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to han...
CVE-2026-11814MEDIUM4.9A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to in...
CVE-2026-11739MEDIUM4.9A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with...
CVE-2026-11738MEDIUM4.3Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t...
CVE-2026-11737MEDIUM4.3Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected ...
CVE-2026-11736LOW1.9A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make ...
CVE-2026-11735LOW1.9A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to ma...
CVE-2026-11734LOW1.1A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected de...
CVE-2026-11733LOW1.1A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the ...
CVE-2025-31114CRITICAL9.3Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code ex...