CVE Vulnerability Database
Search and browse 390,869 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-91201 | MEDIUM | 5.4 | — | Sep 14, 2026 | DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint ... |
| CVE-2026-91200 | HIGH | 8.8 | — | Sep 14, 2026 | DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attack... |
| CVE-2026-91199 | MEDIUM | 5 | — | Sep 14, 2026 | Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetch... |
| CVE-2026-91198 | MEDIUM | 5.3 | — | Sep 14, 2026 | GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by una... |
| CVE-2026-91197 | MEDIUM | 6.5 | — | Sep 14, 2026 | Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFa... |
| CVE-2026-90835 | LOW | 3.5 | — | Sep 14, 2026 | A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the ... |
| CVE-2026-90831 | MEDIUM | 5.3 | — | Sep 14, 2026 | A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the fi... |
| CVE-2026-90830 | MEDIUM | 5.3 | — | Sep 14, 2026 | A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of t... |
| CVE-2026-90829 | MEDIUM | 5.3 | — | Sep 14, 2026 | A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the f... |
| CVE-2026-81900 | HIGH | 7.3 | — | Sep 14, 2026 | Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them int... |
| CVE-2026-77191 | LOW | 2.6 | — | Sep 14, 2026 | An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricte... |
| CVE-2026-75945 | LOW | 2.6 | — | Sep 14, 2026 | A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued. |
| CVE-2026-75944 | LOW | 2.6 | — | Sep 14, 2026 | A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the Acl... |
| CVE-2026-75943 | LOW | 2.6 | — | Sep 14, 2026 | A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the cle... |
| CVE-2026-18116 | HIGH | 7.3 | — | Sep 14, 2026 | Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in ... |
| CVE-2026-14986 | MEDIUM | 6.8 | — | Sep 14, 2026 | The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGE... |
| CVE-2026-91181 | MEDIUM | 6.5 | — | Sep 14, 2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team obje... |
| CVE-2026-91146 | MEDIUM | 6.1 | — | Sep 14, 2026 | Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, a... |
| CVE-2026-91145 | HIGH | 7.1 | — | Sep 14, 2026 | Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to ... |
| CVE-2026-91144 | HIGH | 7.5 | — | Sep 14, 2026 | ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoi... |
| CVE-2026-91143 | HIGH | 7.2 | — | Sep 14, 2026 | goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated... |
| CVE-2026-90828 | MEDIUM | 5.3 | — | Sep 14, 2026 | A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible ... |
| CVE-2026-90827 | LOW | 3.3 | — | Sep 14, 2026 | A vulnerability was identified in GPAC 26.07.0. This affects the function gf_node_deactivate_ex of the file scenegraph/b... |
| CVE-2026-90826 | LOW | 2.8 | — | Sep 14, 2026 | A vulnerability was determined in GPAC 26.07.0. Affected by this issue is the function gf_node_del of the file scenegrap... |
| CVE-2026-90825 | LOW | 3.3 | — | Sep 14, 2026 | A vulnerability was found in GPAC 26.07.0. Affected by this vulnerability is the function gf_node_unregister of the file... |
