CVE Vulnerability Database

Search and browse 375,948 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-30241HIGH8.6Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input pro...
CVE-2025-30240MEDIUM5.1The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By ...
CVE-2025-30239HIGH8.5In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive co...
CVE-2025-30238HIGH8.6In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to e...
CVE-2025-30237HIGH8.7The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not c...
CVE-2026-72919MEDIUM4.3Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7...
CVE-2026-72918MEDIUM5.4Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7...
CVE-2026-72917MEDIUM5.9AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-72916MEDIUM6.3Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-be...
CVE-2026-72915HIGH7.5Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta...
CVE-2026-72914HIGH7.5Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-be...
CVE-2026-6426MEDIUM4.4A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size...
CVE-2025-32736MEDIUM4.9Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may all...
CVE-2026-73035MEDIUM5.3npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability t...
CVE-2026-73033HIGH7Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmi...
CVE-2026-73030HIGH8.1unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory func...
CVE-2026-72913HIGH7.3Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/wind...
CVE-2026-72912MEDIUM4.3CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-rec...
CVE-2026-72911CRITICAL9.9ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_templat...
CVE-2026-72910HIGH7.1ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, p...
CVE-2026-72909HIGH7.1ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayabl...
CVE-2026-72908MEDIUM6.5ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template...
CVE-2026-72907MEDIUM6.5ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function ...
CVE-2026-72906MEDIUM4.3ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email ...
CVE-2026-72905Rejected reason: Further research determined the issue is not a vulnerability.