CVE Vulnerability Database

Search and browse 384,318 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-45811HIGH7.5Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket tr...
CVE-2026-16743MEDIUM5.5A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root ...
CVE-2026-16730MEDIUM5.5A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer set...
CVE-2026-15810HIGH8.7A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.6...
CVE-2026-15243HIGH7.4Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches th...
CVE-2026-10610HIGH8.5Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user.
CVE-2026-7483HIGH8.5Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a...
CVE-2026-16634CRITICAL9.8TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is ...
CVE-2026-15663MEDIUM4.9The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injecti...
CVE-2026-15401HIGH7.2The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbf...
CVE-2026-10033HIGH7.3The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,...
CVE-2026-63317MEDIUM5.6Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected:...
CVE-2026-56392LOW1.8GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation...
CVE-2026-56391MEDIUM4.6GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--ch...
CVE-2026-49745HIGH7.8Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ...
CVE-2026-49744HIGH7.8Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ...
CVE-2026-49743HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of...
CVE-2026-24727CRITICAL9.3An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporat...
CVE-2026-15821MEDIUM6.4The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2026-15739MEDIUM6.4The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' ...
CVE-2026-15704CRITICAL9.8In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authori...
CVE-2026-15346MEDIUM6.1The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '...
CVE-2026-12702MEDIUM4.9In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to...
CVE-2026-16910MEDIUM5.5A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers acc...
CVE-2026-16519HIGH7.3A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads on...