CVE Vulnerability Database

Search and browse 386,734 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-43945HIGH8.9FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthent...
CVE-2026-35290CRITICAL9.8Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita...
CVE-2026-35287HIGH7.5Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita...
CVE-2026-34316MEDIUM6.1Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center). T...
CVE-2026-21954MEDIUM4.3Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobi...
CVE-2026-21953LOW3.3Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobi...
CVE-2026-16484HIGH7.3A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unkn...
CVE-2026-10680HIGH7.6The Classic (BR/EDR) L2CAP signaling handlers l2cap_br_conf_req() and l2cap_br_conf_rsp() in subsys/bluetooth/host/class...
CVE-2026-10679MEDIUM5.5The DesignWare SPI driver (drivers/spi/spi_dw.c) computed the SPI BAUDR clock divider as info->clock_frequency / config-...
CVE-2026-10678HIGH8.1The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes pseudo-register writ...
CVE-2026-10677MEDIUM6.5The CONFIG_USERSPACE syscall verifier z_vrfy_k_poll() in kernel/poll.c allocates a kernel-side copy of the user-supplied...
CVE-2026-10675MEDIUM6.5In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_adv.c), prov_msg_recv() rescheduled the ...
CVE-2026-10674MEDIUM5.5The NXP LPUART serial driver (drivers/serial/uart_mcux_lpuart.c), when CONFIG_UART_USE_RUNTIME_CONFIGURE is enabled, cal...
CVE-2026-8983CRITICAL9.8Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorizati...
CVE-2026-8982HIGH8.1Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vend...
CVE-2026-65058MEDIUM5.9Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip155...
CVE-2026-65057CRITICAL9.3Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make...
CVE-2026-65056HIGH8.3mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal netw...
CVE-2026-65055MEDIUM6.9Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full m...
CVE-2026-65054HIGH8.2MediaCMS 8.2.0 contains an information disclosure vulnerability that allows authenticated users to expose private media ...
CVE-2026-64881HIGH8.8The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command exe...
CVE-2026-64822MEDIUM6.9djangoSIGE through 1.10 (commit a6fe7e8) contains a user enumeration vulnerability in ForgotPasswordView within djangosi...
CVE-2026-64821MEDIUM5.3djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that allows unauthenticated...
CVE-2026-63764HIGH8.6LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _lo...
CVE-2026-63358HIGH8.4FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to P...