CVE Vulnerability Database

Search and browse 383,811 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-16339Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-67595CRITICAL9.2VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template re...
CVE-2026-18060Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-15157MEDIUM5.4undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type he...
CVE-2026-14643HIGH7.5undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or priva...
CVE-2025-69949HIGH7.3kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters em...
CVE-2025-69945HIGH7.3kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.
CVE-2025-69944HIGH7.3kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the vie...
CVE-2025-69943CRITICAL9.8kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and ...
CVE-2025-69942CRITICAL9.8kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.
CVE-2025-67408HIGH7.3Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter ...
CVE-2025-67407HIGH7.3Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters...
CVE-2025-67406HIGH7.3https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execu...
CVE-2025-67405HIGH7.3Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the param...
CVE-2025-67404CRITICAL9.8Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters ...
CVE-2025-67403CRITICAL9.8Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the paramete...
CVE-2026-67439MEDIUM4.3OliveTin gives safe and simple access to predefined shell commands from a web interface. Prior to 3000.17.0, the service...
CVE-2026-67438MEDIUM6.6OliveTin gives access to predefined shell commands from a web interface. From 3000.2.0 until 3000.17.0, the service/inte...
CVE-2026-67437HIGH7.5OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/inte...
CVE-2026-65975MEDIUM6.5Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 u...
CVE-2026-54249MEDIUM6.8Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and...
CVE-2026-50782HIGH7.5Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manage...
CVE-2026-46678MEDIUM5.9Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when...
CVE-2026-16728MEDIUM6.5undici's retry interceptor can deliver a response whose body length does not match the Content-Length header exposed to ...
CVE-2026-13309MEDIUM6.8Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerabili...