CVE Vulnerability Database

Search and browse 390,004 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-55880HIGH7.1OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlier, three dashboard and note mutation functions ran...
CVE-2026-55879CRITICAL9.3OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom ...
CVE-2026-55665HIGH8.5Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, Grist contained two cross-site scri...
CVE-2026-55664MEDIUM4.3Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, the GET /forms endpoint read table ...
CVE-2026-55659HIGH7.7Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, several server-rendered Grist pages...
CVE-2026-55405HIGH7.6LangChain4j is a Java library for building LLM-powered applications on the JVM. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.1...
CVE-2026-55233HIGH7.5OpenResty is a high performance web platform. From 1.29.2.1 to before 1.29.2.5, an out-of-bounds write vulnerability exi...
CVE-2026-55229HIGH7.5Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.34.0, Gotenberg's /forms/libreoffice/convert endpo...
CVE-2026-55213HIGH7.5h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit edd7a120bfc4af11ac0cbebce2a43cc1f93f...
CVE-2026-45203HIGH7.8Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memor...
CVE-2026-45196HIGH7.8Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU r...
CVE-2026-41154HIGH7.8Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls. ...
CVE-2026-34196HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an integer overflow a...
CVE-2026-13039MEDIUM5.3The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to a...
CVE-2026-12761CRITICAL9.8The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to auth...
CVE-2026-57850HIGH8.7RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a l...
CVE-2026-57158CRITICAL9.1FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GF...
CVE-2026-57157MEDIUM6.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, FreeRDP server implementations with th...
CVE-2026-57156CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients conta...
CVE-2026-55827HIGH8.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.1, FreeRDP clients launched with the non-...
CVE-2026-55789HIGH8.5Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML app...
CVE-2026-55515MEDIUM5Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authoriz...
CVE-2026-55481MEDIUM4.8Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related br...
CVE-2026-55479MEDIUM4.3Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorize...
CVE-2026-55475MEDIUM5.7Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV impo...