CVE Vulnerability Database

Search and browse 375,948 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-15562HIGH7.5A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and...
CVE-2026-15561HIGH7.5A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an at...
CVE-2026-15560HIGH8.1when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmars...
CVE-2026-15556HIGH8.1A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching th...
CVE-2026-15555HIGH8.8A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via ...
CVE-2026-15554HIGH7.4the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authenti...
CVE-2026-10579CRITICAL9.8A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no v...
CVE-2026-73156MEDIUM5.3Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap t...
CVE-2026-73155MEDIUM5.3Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first ...
CVE-2026-73140MEDIUM5.3Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report ex...
CVE-2026-19519MEDIUM4.3A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked...
CVE-2026-19418HIGH7.3The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, wher...
CVE-2026-19518MEDIUM6.5Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipu...
CVE-2026-19517MEDIUM6.5Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerabilit...
CVE-2026-19391MEDIUM6.5A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the ...
CVE-2026-16053HIGH8.5Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Tr...
CVE-2026-8158MEDIUM5.3The Signed Video Framework contained a  buffer overflow issue which could lead the application using this framework to ...
CVE-2026-6505MEDIUM5.1The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to priv...
CVE-2026-6181MEDIUM5.9The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after...
CVE-2026-5304MEDIUM5.7An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerabil...
CVE-2026-5303MEDIUM5.7The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to priv...
CVE-2026-4757HIGH7.2A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege...
CVE-2026-19516CRITICAL9.1A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the graf...
CVE-2026-18348MEDIUM4.1Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst...
CVE-2026-14549MEDIUM4.3The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of ...