CVE search

401,022 results
CVE-2026-56661HIGHGetSimple CMS: Server-Side Request Forgery in the UpdateCE update endpointEPSS 0.3%CVE-2026-56660CRITICALGetSimple CMS: CSRF, SSRF, and Unrestricted Zip ExtractionEPSS 0.5%CVE-2026-53953CRITICALGetSimple CMS: Predictable Password Reset Password Allows Administrator Account TakeoverEPSS 0.3%CVE-2026-104286CRITICALAn improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FEPSS 1.8%CVE-2026-27872MEDIUMEasyIO FGEPSS 0.1%CVE-2026-84682HIGHTDDPv2 setProductVer Command Injection in Archer AX90EPSS 1.0%CVE-2026-55232HIGHVvveb: Server-side request forgery in Vvveb via IPv6 bypass of validateUrl() in editor oEmbed proxyEPSS 0.3%CVE-2026-55230HIGHVvveb: Stored XSS in Vvveb via sanitizeHTML() filter bypass using a quoted greater-than characterEPSS 0.3%CVE-2026-55231HIGHVvveb: Path traversal in Vvveb via sanitizeFileName() bypass enables arbitrary file read and delete through backup toolsEPSS 0.5%CVE-2026-15911HIGHConfluent Kafka Python Improper TLS Certificate ValidationEPSS 0.2%CVE-2026-104059HIGHLektor 3.3.14 CSRF via Admin API EndpointsEPSS 0.1%CVE-2026-8618HIGHPre-Authentication Stack-based Buffer Overflow Remote Code Execution in TDDPv2 Subtype 0x91 on Deco M9 PlusEPSS 0.2%CVE-2026-104058MEDIUMPodgrab Missing Authentication on WebSocket /ws EndpointEPSS 0.2%CVE-2026-104057HIGHPodgrab Unauthenticated DoS via Concurrent Map Access in WebSocket HandlerEPSS 0.3%CVE-2026-104056—CVE-2026-104056EPSS 0.1%CVE-2026-55083CRITICALDHIS2: Unsafe Java Deserialization - Remote Code Execution (RCE)EPSS 0.6%CVE-2026-102369HIGHUnauthenticated Remote Code Execution via MacTool Command Injection in TP-Link Tapo C120 & C200EPSS 0.2%CVE-2026-78578HIGHUnauthenticated do Method Onboarding Connect Allows Wi‑Fi Reconfiguration Denial of Service Vulnerability in TP-Link Tapo C120 & C200EPSS 0.2%CVE-2026-78577MEDIUMUnauthenticated Onboarding Scan Information Disclosure in TP-Link Tapo C120 & C200EPSS 0.1%CVE-2026-9032HIGHUnauthenticated Onboarding Connect NULL Pointer Dereference Denial of Service Vulnerability in TP-Link Tapo C120 & C200EPSS 0.1%