CVE Vulnerability Database

Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-45368HIGH8.4Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the underlying URL methods for ...
CVE-2026-45334MEDIUM5.3Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the content-locking feature ret...
CVE-2026-44180CRITICAL9.8Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kuber...
CVE-2026-44177HIGH8.8Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correct...
CVE-2026-44176MEDIUM6Kirby is an open-source content management system. Versions prior to 4.9.1 and 5.4.1 do not check the `pages.access` per...
CVE-2026-44175HIGH8.5Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, Kirby did not securely sanitize...
CVE-2026-44174HIGH8.7Kirby is an open-source content management system. Prior to 4.9.1 and 5.4.1, Kirby did not validate the model attributes...
CVE-2026-14782MEDIUM4.9The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Cu...
CVE-2026-13713MEDIUM6.2YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on ...
CVE-2026-61378MEDIUM6.8A divide-by-zero vulnerability in the Productivity Suite allows a local attacker to cause a division by zero leading to...
CVE-2026-60073MEDIUM5.9An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB ...
CVE-2026-57896MEDIUM6.9An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupti...
CVE-2026-55173HIGH8.1WWBN AVideo is an open source video platform. Versions 29.0 and below remain vulnerable to OS command injection because ...
CVE-2026-53410HIGH7A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Cl...
CVE-2026-53409HIGH7.8Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct ...
CVE-2026-44023HIGH8.6Docling Core defines core data types and transformations for the document processing application Docling. In versions 1....
CVE-2026-44019HIGH8.1Docling Core defines core data types and transformations for the document processing application Docling. In versions 2....
CVE-2026-38158CRITICAL9.8A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to acc...
CVE-2026-36425MEDIUM6.5An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user...
CVE-2026-33731MEDIUM6.5WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/Aut...
CVE-2026-33692HIGH7.5WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through ...
CVE-2026-11889HIGH7.1SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation at...
CVE-2024-34268HIGH7.1EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow ...
CVE-2024-32389LOW3.5Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attack...
CVE-2024-32387MEDIUM5.7An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitiv...