CVE Vulnerability Database

Search and browse 389,990 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-55804MEDIUM5.9Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow...
CVE-2026-55803MEDIUM5.9Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow...
CVE-2026-55187MEDIUM5.8Mailpit is an email testing tool and API for developers. Prior to 1.30.2, the remediation shipped for CVE-2026-27808 is ...
CVE-2026-54736HIGH8.2Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the...
CVE-2026-52761MEDIUM5.3ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0....
CVE-2026-52747HIGH8.6ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to ...
CVE-2026-49844MEDIUM5.9Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces ...
CVE-2026-49394HIGH7.1Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_pag...
CVE-2026-49213HIGH8.1TypeBot is a chatbot builder tool. Prior to 3.17.2, Typebot's shared SSRF validator in packages/lib/src/ssrf/validateHtt...
CVE-2026-48127MEDIUM5.3Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach...
CVE-2026-47422MEDIUM5.3Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked approp...
CVE-2026-47199LOW2.3Frappe is a full-stack web application framework. Prior to 16.18.3 and 15.108.0, check_safe_sql_query permitted SELECT I...
CVE-2026-44795HIGH8.8Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3...
CVE-2026-42219MEDIUM6.9Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, path traversal via download_backups was...
CVE-2026-41482HIGH7.1Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion wer...
CVE-2026-15085MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI SEO/GEO ...
CVE-2026-15084MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Patterns...
CVE-2026-15083MEDIUM4.2Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Cond...
CVE-2026-15082MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Siteimprove...
CVE-2026-15081HIGH7.4Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Se...
CVE-2026-15080MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery. ...
CVE-2026-15079MEDIUM5.4Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute Force. This...
CVE-2026-13244HIGH8.1Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Ma...
CVE-2026-13243MEDIUM4.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. This issue...
CVE-2026-13242MEDIUM6.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation...