CVE Vulnerability Database

Search and browse 390,004 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-12535CRITICAL9.8Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field a...
CVE-2026-11909LOW3.3Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examp...
CVE-2026-11908MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allo...
CVE-2026-10770MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam b...
CVE-2026-10769MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Commerce Co...
CVE-2026-10768CRITICAL9.8Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov W...
CVE-2026-9726CRITICAL9.8Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal Alternativ...
CVE-2026-7639HIGH7.8Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use afte...
CVE-2026-58499HIGH8.2EverOS is a memory runtime for agents. Prior to 1.0.1, EverOS is vulnerable to path traversal in the POST /api/v1/memory...
CVE-2026-57807CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Si...
CVE-2026-57575MEDIUM6.9Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a Server-Side Request Fo...
CVE-2026-57574HIGH7.4Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a vulnerability in Time-...
CVE-2026-57230MEDIUM5.4OpenReplay is a self-hosted session replay suite. Prior to 1.27.0, the session search and analytics API in enterprise ed...
CVE-2026-57221MEDIUM5RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform aut...
CVE-2026-57220HIGH7.5RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configur...
CVE-2026-57219HIGH7.5RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth en...
CVE-2026-57218MEDIUM6.5RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep re...
CVE-2026-57217MEDIUM6.5RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization ...
CVE-2026-57216CRITICAL10RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Str...
CVE-2026-57215HIGH8.8RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindi...
CVE-2026-57214MEDIUM5.4RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose ...
CVE-2026-57213MEDIUM4.8RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_manag...
CVE-2026-57212HIGH7.7RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP ...
CVE-2026-57211CRITICAL10RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin stati...
CVE-2026-55881HIGH7.1OpenReplay is a self-hosted session replay suite. From 1.22.0 before 1.27.0, getFirstMob returned 15-second presigned S3...