CVE search
369,487 resultsCVE-2026-44268MEDIUMDell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 0.1%CVE-2026-44269MEDIUMDell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 0.1%CVE-2026-10055HIGHIn Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connecteEPSS 0.3%CVE-2026-13341HIGHPrompt Injection and Credential Exposure via Untrusted Analytics Data in Kong Konnect MCPEPSS 0.3%CVE-2026-10054HIGHIn affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shellEPSS 0.2%CVE-2026-5137MEDIUMRTMKit <= 2.0.7 - Authenticated (Contributor+) Limited Local File Inclusion via 'template' ParameterEPSS 0.3%CVE-2026-4322MEDIUMXSS in Raera's DestekzEPSS 0.1%CVE-2026-4321CRITICALSQLi in Raera's DestekzEPSS 0.3%CVE-2026-35159MEDIUMDell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical accEPSS 0.2%CVE-2026-11398MEDIUMLatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer StepEPSS 0.3%CVE-2026-4804MEDIUMZakra <= 4.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta REST APIEPSS 0.2%CVE-2026-9756MEDIUMGenerateBlocks <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link AttributeEPSS 0.2%CVE-2026-11778MEDIUMCURCY <= 2.2.14 - Unauthenticated Arbitrary Shortcode Execution via 'exchange' ParameterEPSS 0.3%CVE-2026-11900MEDIUMAd Inserter <= 2.8.16 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Content Disclosure via 'data' Shortcode AttributeEPSS 0.3%CVE-2026-47896HIGHApache Lucene.Net: Unauthenticated arbitrary file read on the Lucene.Net.Replicator replication serverEPSS 0.7%CVE-2026-47897HIGHApache Lucene.Net: Arbitrary file write from malicious server to Lucene.Net.Replicator clientEPSS 0.6%CVE-2026-47898MEDIUMApache Lucene.Net: XXE vulnerability in Lucene.Net.Analysis.Common PatternParserEPSS 0.3%CVE-2026-8804MEDIUMCleartext Storage of Sensitive Information for Puppet Resource APIEPSS 0.1%CVE-2026-14544CRITICALHplip: incomplete fix for cve-2026-8631EPSS 0.6%CVE-2026-9148HIGHComments <= 7.6.56 - Unauthenticated Stored Cross-Site Scripting via 'Website' FieldEPSS 0.3%