CVE Vulnerability Database

Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-63306CRITICAL9.2stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed e...
CVE-2026-63305CRITICAL9.2AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and ...
CVE-2026-63304CRITICAL9.2AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the list...
CVE-2026-12391MEDIUM5An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) with...
CVE-2026-11386CRITICAL9An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools)....
CVE-2025-71388HIGH7.6stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission ...
CVE-2025-71377HIGH8.7stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching me...
CVE-2024-58360MEDIUM6.9stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verifica...
CVE-2026-59249MEDIUM6.3Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malici...
CVE-2026-35149HIGH8.2HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized us...
CVE-2026-35148MEDIUM6.3HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints ar...
CVE-2026-35147HIGH8.2HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verif...
CVE-2026-35146MEDIUM6.3HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish conn...
CVE-2023-49900CRITICAL9.8An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in t...
CVE-2023-49899CRITICAL9.8An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the ori...
CVE-2026-22752CRITICAL9.6Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affe...
CVE-2026-7543HIGH7.2The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions ...
CVE-2026-6424MEDIUM6.7Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the syste...
CVE-2026-6423HIGH8.5A local privilege escalation vulnerability in ESET Inspect Connector.  The vulnerability was caused by improper authenti...
CVE-2026-58078HIGH8.7Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extensio...
CVE-2026-15727MEDIUM4.9The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the 'delete_user_roles' parameter in ...
CVE-2026-15651MEDIUM4.9The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' para...
CVE-2026-15610MEDIUM4.3The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorizatio...
CVE-2026-15407MEDIUM4.3The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7...
CVE-2026-15350MEDIUM4.3The The Cache Purger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2....