CVE Vulnerability Database

Search and browse 390,004 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-54329HIGH7.7Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request ...
CVE-2026-53450HIGH7.4Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, coturn rejects loopback peers by d...
CVE-2026-53449MEDIUM6Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI co...
CVE-2026-53448HIGH7.2Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.12.0, the coturn HTTPS admin panel passe...
CVE-2026-15146MEDIUM5.9GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malici...
CVE-2025-30008MEDIUM5.4HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users...
CVE-2025-30007HIGH8.8HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticat...
CVE-2026-57476MEDIUM6.3Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additio...
CVE-2026-57475MEDIUM6.9Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed ...
CVE-2026-57474MEDIUM6.9Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accept...
CVE-2026-56668HIGH8.1ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for ur...
CVE-2026-56667HIGH7.3ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL Login V2 OIDC and SAML FailedPreconditi...
CVE-2026-56666MEDIUM4.8ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler ch...
CVE-2026-56665MEDIUM4.2ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL is an open source identity m...
CVE-2026-56664MEDIUM4.2ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Prov...
CVE-2026-55672HIGH7.4ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchan...
CVE-2026-55671LOW2.3ZITADEL is an open source identity management platform. From 4.0.0-rc.1 through 4.15.1, ZITADEL's HTTP notification chan...
CVE-2026-55670LOW2.3ZITADEL is an open source identity management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the...
CVE-2026-53780Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-2397CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automa...
CVE-2026-59193MEDIUM4.9Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by ...
CVE-2026-59190HIGH8.7grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages. In 1.10.5...
CVE-2026-59180LOW3.1Apprise is an open source library which allows you to send a notification to almost all of the most popular notification...
CVE-2026-59162HIGH7.5Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses...
CVE-2026-59161HIGH7.5Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming w...