CVE Vulnerability Database

Search and browse 389,984 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-15512MEDIUM6.3A vulnerability was identified in pig-mesh Pig up to 3.9.2. Affected by this issue is some unknown functionality of the ...
CVE-2026-15511CRITICAL9.8A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function sy...
CVE-2026-15510MEDIUM6.3A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. T...
CVE-2026-15509MEDIUM6.3A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON...
CVE-2026-15508MEDIUM6.3A flaw has been found in Helicone ai-gateway up to 0.2.0-beta.30. This affects the function build_target_url of the file...
CVE-2026-15507MEDIUM6.3A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file ...
CVE-2026-15506HIGH7.8A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown func...
CVE-2026-15505LOW3.5A weakness has been identified in vnotex vnote up to 3.20.1. Impacted is an unknown function of the file /src/data/extra...
CVE-2026-10668MEDIUM4.6The Nuvoton NuMaker HSUSBD USB device-controller driver (drivers/usb/udc/udc_numaker.c) armed the control Data IN stage ...
CVE-2026-10667HIGH7.8Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-l...
CVE-2026-10666CRITICAL9.8parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the...
CVE-2026-10665HIGH7.4In Zephyr's WireGuard subsystem (subsys/net/lib/wireguard), wg_process_data_message() in wg_crypto.c linearizes an inbou...
CVE-2026-10664MEDIUM5The nRF70 Wi-Fi driver's power-save event handler nrf_wifi_event_proc_get_power_save_info() in drivers/wifi/nrf_wifi/src...
CVE-2026-10663MEDIUM6.1In Zephyr's experimental USB host stack (CONFIG_USB_HOST_STACK), usbh_device_disconnect() (subsys/usb/host/usbh_device.c...
CVE-2026-58596HIGH8.3Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges o...
CVE-2026-15502MEDIUM6.3A vulnerability was detected in AojiaoZero Antaris 1.0. This affects the function _rewardPurchase of the file /ipn.php o...
CVE-2026-15501MEDIUM6.3A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function T...
CVE-2026-61876CRITICAL9.4LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent networ...
CVE-2026-61875HIGH8.8luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject Jav...
CVE-2026-61874LOW3.1filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, all...
CVE-2026-59260HIGH8.8OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users t...
CVE-2026-56336MEDIUM6.9Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain ...
CVE-2026-56313HIGH8.1Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that al...
CVE-2026-56308HIGH8.4Capgo before 12.128.2 allows email address changes without requiring current password re-authentication or verification ...
CVE-2026-56281MEDIUM5.1Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit p...