CVE Vulnerability Database

Search and browse 389,869 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-13439CRITICAL9.8The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Admin...
CVE-2023-37507HIGH7.5HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon...
CVE-2026-15156MEDIUM6.4The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored ...
CVE-2023-37508MEDIUM6.1HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this v...
CVE-2026-59776HIGH7Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the v...
CVE-2026-16336MEDIUM5.3A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/jav...
CVE-2026-6952HIGH7.2A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B...
CVE-2026-63729MEDIUM6.8The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince co...
CVE-2026-16334MEDIUM6.3A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code o...
CVE-2026-16332HIGH7.3A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_upload...
CVE-2026-16331HIGH7.3A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/fu...
CVE-2026-16330HIGH7.3A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jqu...
CVE-2026-16329HIGH7.3A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/up...
CVE-2026-63728HIGH8.1Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence r...
CVE-2026-55833HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2...
CVE-2026-55831HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2...
CVE-2026-16327HIGH7.3A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_...
CVE-2026-15905HIGH7.8Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap cor...
CVE-2026-15904HIGH8.8Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user...
CVE-2026-15903HIGH8.8Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitra...
CVE-2026-15902HIGH8.8Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code insi...
CVE-2026-15901CRITICAL9.6Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap...
CVE-2026-15900CRITICAL9.6Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perfo...
CVE-2026-15899CRITICAL9.6Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially...
CVE-2026-64626MEDIUM6.4AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the en...