CVE Vulnerability Database

Search and browse 383,946 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-43871HIGH7.5Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings....
CVE-2026-41608HIGH7.5Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This i...
CVE-2026-14856MEDIUM6.3A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter ...
CVE-2026-12495MEDIUM5.3Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys M...
CVE-2026-40000LOW1.8The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compre...
CVE-2026-17534MEDIUM5.5Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal ...
CVE-2026-17527HIGH7.7In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only acc...
CVE-2026-17523HIGH7.8A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, where an unprivileged local user can exploit this vul...
CVE-2026-65765MEDIUM6.9Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper limitation of paths...
CVE-2026-65764MEDIUM5.1Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user i...
CVE-2026-16554MEDIUM5.1cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. Th...
CVE-2026-15799Rejected reason: This is a duplicate.
CVE-2026-65894HIGH8.7This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacke...
CVE-2026-65893HIGH7This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An atta...
CVE-2026-64536HIGH8.1In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in is_ap_in_tkip(...
CVE-2026-64535CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch S...
CVE-2026-64534CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_unini...
CVE-2026-64533HIGH7.8In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate lcns_follow in log_replay conver...
CVE-2026-64532HIGH7.8In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound NTFS_DE view.data_off in UpdateReco...
CVE-2026-64531HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action at...
CVE-2026-14837HIGH8.5Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism...
CVE-2026-9830HIGH8.2The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission cal...
CVE-2026-66412HIGH7.1Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read mileston...
CVE-2026-14827MEDIUM6.8The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it in...
CVE-2026-14820MEDIUM5.3The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-log...