CVE Vulnerability Database

Search and browse 384,300 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-57106CRITICAL10Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56163CRITICAL10Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el...
CVE-2026-55732HIGH8.7Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-R...
CVE-2026-55731MEDIUM6.6Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI...
CVE-2026-55730HIGH8.7Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenti...
CVE-2026-55729HIGH7.7Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all pla...
CVE-2026-55728LOW3.8Stack-based Buffer Overflow (CWE-121) in `/usr/bin/ltsudo` `cmd_ipaddr_conflict` in Loytec LIP-ME201C, L-INX, L-GATE, L...
CVE-2026-49326MEDIUM6.5Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest...
CVE-2026-17059MEDIUM6.5A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloa...
CVE-2026-16802MEDIUM6.5Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and ear...
CVE-2026-16801HIGH8.8Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2...
CVE-2026-16800HIGH8.8Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 20...
CVE-2026-16799MEDIUM5Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and ...
CVE-2026-16798MEDIUM6.5Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2....
CVE-2026-12504HIGH8.4Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-...
CVE-2026-12503CRITICAL9.2Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-...
CVE-2026-12502HIGH8.4Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, ...
CVE-2026-12496HIGH8.7Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-I...
CVE-2026-17048MEDIUM4.9A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs w...
CVE-2026-9765HIGH7.1Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are ...
CVE-2026-7484MEDIUM5.3External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Fu...
CVE-2026-66144HIGH7.5Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the ...
CVE-2026-66143HIGH7.5It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2...
CVE-2026-66142HIGH7.5Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested s...
CVE-2026-66010MEDIUM6.1DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDL...