CVE Vulnerability Database

Search and browse 389,990 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-15089CRITICAL9.1Vulnerability in Drupal Commerce guest registration. This issue affects Commerce guest registration versions: *.*.
CVE-2026-15087MEDIUM5.9vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.
CVE-2026-15086MEDIUM5.9vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter...
CVE-2026-14480CRITICAL9.9OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload wor...
CVE-2026-14286Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-11915MEDIUM5.9vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions...
CVE-2026-11914MEDIUM5.9vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*.
CVE-2026-11913CRITICAL9.8vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.
CVE-2026-59155MEDIUM6.9Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to 2.2.5, the GET ...
CVE-2026-58591MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox al...
CVE-2026-58590MEDIUM5.4Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: f...
CVE-2026-58589MEDIUM5.4Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: f...
CVE-2026-58588MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canv...
CVE-2026-58587MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canv...
CVE-2026-58503MEDIUM6.9Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via...
CVE-2026-57584HIGH8.7Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.0, every Phalcon MVC application built with a def...
CVE-2026-55884CRITICAL9.2Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP...
CVE-2026-55883HIGH8.3Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.24.0 through 0.37.3, the Tilt HUD WebS...
CVE-2026-55882HIGH8.3Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.19.5 through 0.37.3, the Tilt HUD serv...
CVE-2026-55852HIGH8.6Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, TarSlip RCE was possible in Package Imp...
CVE-2026-55810HIGH8.1Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphin...
CVE-2026-55809HIGH8.1Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance f...
CVE-2026-55808MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core...
CVE-2026-55807LOW3.1Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue af...
CVE-2026-55806MEDIUM5.9URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This is...