CVE Vulnerability Database

Search and browse 375,630 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-64952MEDIUM6.5The hunt_delete() VQL function allows deleting hunts.  Velociraptor misapplied the permission check requiring only COLL...
CVE-2026-64951LOW3.5A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic...
CVE-2026-18663MEDIUM5.9A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Sess...
CVE-2026-18652MEDIUM4.9Velociraptor allows reading Stacked result sets from the GUI.  Velociraptor's multi-tenant design stores sub orgs within...
CVE-2026-67283MEDIUM6.9Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenti...
CVE-2026-67282CRITICAL10Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker ...
CVE-2026-19566Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix ...
CVE-2026-19426HIGH8.8POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directl...
CVE-2025-41771MEDIUM5.3An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerabl...
CVE-2025-41770HIGH7.5An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an rem...
CVE-2025-41769CRITICAL9.8The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. A...
CVE-2026-66659CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome ...
CVE-2026-19594HIGH8.1Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-dep...
CVE-2026-19217The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTM...
CVE-2026-19073MEDIUM5.3The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one o...
CVE-2026-19052MEDIUM4.3The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX ac...
CVE-2026-19050MEDIUM6.4The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the ca...
CVE-2026-18962MEDIUM4.3The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload int...
CVE-2026-18943MEDIUM6.5The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allow...
CVE-2026-18789HIGH7.5The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, ...
CVE-2026-18474HIGH8.6The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL sta...
CVE-2026-18391The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stor...
CVE-2026-18366The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access ...
CVE-2026-18230The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL sta...
CVE-2026-18057The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it i...