CVE Vulnerability Database

Search and browse 389,949 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-15804HIGH8.8The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands ...
CVE-2026-15583HIGH8.6A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's enviro...
CVE-2026-14251HIGH7.7A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when ...
CVE-2026-42936HIGH8.4The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory wh...
CVE-2026-12512HIGH8.6The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before us...
CVE-2026-12281HIGH8.1The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without ...
CVE-2026-11580MEDIUM5.5The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capab...
CVE-2026-11579MEDIUM5.3The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload ...
CVE-2026-8920HIGH8.5Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wa...
CVE-2026-8919HIGH7.2Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local us...
CVE-2026-15030MEDIUM5.6Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows ...
CVE-2026-15029HIGH8.4Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Mana...
CVE-2026-13585HIGH8.2Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in ...
CVE-2026-13385CRITICAL9.5An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows...
CVE-2026-11851MEDIUM5.9Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of ...
CVE-2026-9770MEDIUM5.3Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is s...
CVE-2026-13230MEDIUM6.5An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechan...
CVE-2026-5270CRITICAL9.8An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage...
CVE-2026-5269CRITICAL9.8In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used fo...
CVE-2026-51808CRITICAL9.8Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the open...
CVE-2026-51807CRITICAL9.8Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (...
CVE-2026-36035MEDIUM6.5Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Ser...
CVE-2026-15753MEDIUM5.4A vulnerability was determined in zhinianboke xianyu-auto-reply on Server. Affected by this vulnerability is an unknown ...
CVE-2026-15752HIGH7.3A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is a...
CVE-2026-15751MEDIUM5.3A security vulnerability has been detected in mastergo-design mastergo-magic-mcp up to 0.2.0. The affected element is th...