CVE Vulnerability Database

Search and browse 385,853 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-65876CRITICAL9.2Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of c...
CVE-2026-65766CRITICAL9.2Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of o...
CVE-2026-61511CRITICAL9.8vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::...
CVE-2026-17514MEDIUM5.3A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Ex...
CVE-2026-17513LOW3.3A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected is the function ggml_ftype_to_ggml_type of the file...
CVE-2026-15003MEDIUM5.6A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125...
CVE-2026-59690HIGH8A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M...
CVE-2026-59689HIGH8An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connectio...
CVE-2026-59688HIGH8.4An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M...
CVE-2026-59687HIGH8.4An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M...
CVE-2026-59686HIGH8.4An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M...
CVE-2026-56538LOW3.5An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosi...
CVE-2026-56537LOW3.5HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they ar...
CVE-2026-17512LOW3.3A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This impacts the function log_mel_spectrogram of the fi...
CVE-2026-12991HIGH8.7The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Visio...
CVE-2026-12990HIGH7.7An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simul...
CVE-2026-12989HIGH8.7A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated at...
CVE-2026-66053MEDIUM5.9Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affect...
CVE-2026-58662CRITICAL9.1Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. Thi...
CVE-2026-58389HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects A...
CVE-2026-58023CRITICAL9.1Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Us...
CVE-2026-57917MEDIUM4.8proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially a...
CVE-2026-57916MEDIUM4.6proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare ar...
CVE-2026-55971CRITICAL9.8Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0...
CVE-2026-55970MEDIUM6.5Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users a...