CVE Vulnerability Database

Search and browse 390,004 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-55469MEDIUM6.5Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update p...
CVE-2026-55466HIGH8.7Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP...
CVE-2026-55462MEDIUM4.3Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authoriz...
CVE-2026-55461MEDIUM6.1Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the user edit flow stores url()->previous() from the ...
CVE-2026-55452HIGH7.3Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent ...
CVE-2026-55377HIGH8.1Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's Account Center step-...
CVE-2026-55370MEDIUM6.4Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's existing TOTP verifi...
CVE-2026-54714MEDIUM6.1Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, @logto/core reflected the SA...
CVE-2026-15295MEDIUM4.4The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm...
CVE-2026-11321HIGH7.1The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates user-supplied CSV field values directly into SQL ...
CVE-2026-6872Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-6212HIGH8.8Authorization bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc. TeraMIS allows Pri...
CVE-2026-61461HIGH8.8Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers ...
CVE-2026-61460HIGH8.8Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonController,...
CVE-2026-61459CRITICAL9.8MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubect...
CVE-2026-5801CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics...
CVE-2026-59151CRITICAL9.6Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asser...
CVE-2026-55843MEDIUM6.5Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission...
CVE-2026-55516HIGH7.7Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH or PUT /api/v1/maintenances/{maintenance_id} ch...
CVE-2026-55478MEDIUM5.4Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether th...
CVE-2026-55476MEDIUM4.3Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_...
CVE-2026-55474MEDIUM6.5Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the rout...
CVE-2026-55472MEDIUM4.3Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locati...
CVE-2026-55464MEDIUM5.4Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize jav...
CVE-2026-55460HIGH7.1Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and u...