CVE Vulnerability Database

Search and browse 389,869 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-65051MEDIUM6.9Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability tha...
CVE-2026-65050HIGH7.1Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callb...
CVE-2026-65049CRITICAL9.3Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability th...
CVE-2026-65048CRITICAL9.3Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting ...
CVE-2026-59851HIGH8.8A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the...
CVE-2026-59850HIGH7.5A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invok...
CVE-2026-59849HIGH7.5A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clien...
CVE-2026-56587LOW3.7HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or ma...
CVE-2026-56584MEDIUM5.3HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software...
CVE-2026-47122MEDIUM4.2Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `...
CVE-2026-46681HIGH7.2@nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility library. Prior to version 0.14.0, the _copyProps fu...
CVE-2026-16448MEDIUM6.3A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-32...
CVE-2026-15226HIGH8.4A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler ...
CVE-2026-11876MEDIUM5In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/stack` endpoint (`get_deployed_stack`) lacks proper ...
CVE-2024-5300MEDIUM5.6An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configura...
CVE-2026-9499MEDIUM6.3An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is ...
CVE-2026-59848MEDIUM5.3A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep ...
CVE-2026-59847HIGH7.5A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively re...
CVE-2026-47121MEDIUM6.1Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `re...
CVE-2026-16447HIGH7.3A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader...
CVE-2025-66390CRITICAL9.8In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) ...
CVE-2026-8285MEDIUM4.3Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. FlexCity allows Exces...
CVE-2026-8284MEDIUM6.1URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data ...
CVE-2026-6792MEDIUM6.5Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access ...
CVE-2026-59846LOW3.9A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metachara...