CVE Vulnerability Database

Search and browse 390,869 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-91201MEDIUM5.4DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint ...
CVE-2026-91200HIGH8.8DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attack...
CVE-2026-91199MEDIUM5Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetch...
CVE-2026-91198MEDIUM5.3GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by una...
CVE-2026-91197MEDIUM6.5Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFa...
CVE-2026-90835LOW3.5A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the ...
CVE-2026-90831MEDIUM5.3A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the fi...
CVE-2026-90830MEDIUM5.3A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of t...
CVE-2026-90829MEDIUM5.3A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the f...
CVE-2026-81900HIGH7.3Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them int...
CVE-2026-77191LOW2.6An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricte...
CVE-2026-75945LOW2.6A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.
CVE-2026-75944LOW2.6A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the Acl...
CVE-2026-75943LOW2.6A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the cle...
CVE-2026-18116HIGH7.3Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in ...
CVE-2026-14986MEDIUM6.8The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGE...
CVE-2026-91181MEDIUM6.5Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team obje...
CVE-2026-91146MEDIUM6.1Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, a...
CVE-2026-91145HIGH7.1Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to ...
CVE-2026-91144HIGH7.5ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoi...
CVE-2026-91143HIGH7.2goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated...
CVE-2026-90828MEDIUM5.3A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible ...
CVE-2026-90827LOW3.3A vulnerability was identified in GPAC 26.07.0. This affects the function gf_node_deactivate_ex of the file scenegraph/b...
CVE-2026-90826LOW2.8A vulnerability was determined in GPAC 26.07.0. Affected by this issue is the function gf_node_del of the file scenegrap...
CVE-2026-90825LOW3.3A vulnerability was found in GPAC 26.07.0. Affected by this vulnerability is the function gf_node_unregister of the file...