CVE Vulnerability Database

Search and browse 389,905 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-12701CRITICAL9A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content pa...
CVE-2026-57311MEDIUM5.3Windu CMS does not validate types of uploaded files. An authenticated attacker can upload arbitrary files, including PHP...
CVE-2026-57310MEDIUM6.3Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker...
CVE-2026-57309CRITICAL9.3A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to injec...
CVE-2026-16248HIGH8.8A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the ...
CVE-2026-16244MEDIUM6.3A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected by this vulnerabilit...
CVE-2026-12080HIGH7.3A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-a...
CVE-2026-64623HIGH8.8Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the...
CVE-2026-64622CRITICAL9.3Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/...
CVE-2026-64621CRITICAL9.3FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_appl...
CVE-2026-64620CRITICAL9.1FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypt...
CVE-2026-63763HIGH8.8SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileg...
CVE-2026-63762MEDIUM6.5SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript...
CVE-2026-63761MEDIUM5.3SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with ALGORITHM ES...
CVE-2026-63760HIGH8.7SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processin...
CVE-2026-63759HIGH7.1SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annot...
CVE-2026-63758MEDIUM5.4SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenti...
CVE-2026-63757HIGH8.8SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns at...
CVE-2026-63756CRITICAL9.2SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows...
CVE-2026-63755HIGH7.1SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH clauses i...
CVE-2026-63754HIGH7.1SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WHERE clause...
CVE-2026-63753MEDIUM5.3SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. At...
CVE-2026-63752MEDIUM5.3SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated ...
CVE-2026-63751MEDIUM5.3SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allo...
CVE-2026-63750HIGH7.5SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket c...