CVE Vulnerability Database

Search and browse 390,004 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-59154MEDIUM4.3Wekan is open source kanban built with Meteor. Prior to 9.64, Wekan has a cross-board authorization bypass in the direct...
CVE-2026-58493MEDIUM5.1grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, Database::__call builds PDO DSN strings by dir...
CVE-2026-58492CRITICAL9.2grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its t...
CVE-2026-57167MEDIUM5.1PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, server-side-rendered video watch pages em...
CVE-2026-56675HIGH8.39Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* acce...
CVE-2026-55890MEDIUM4.8Grav is a file-based Web platform. Prior to 2.0.0-rc.9, Grav's incomplete fix for stored XSS through the Markdown media ...
CVE-2026-55885MEDIUM6.8Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download ...
CVE-2026-55783LOW2.4NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's seven in-hous...
CVE-2026-55782LOW2.4NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's WebAssembly a...
CVE-2026-55781LOW2.4NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's UFS and FFS i...
CVE-2026-55780LOW2.4NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's .NET single-f...
CVE-2026-55687HIGH7.5ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. Versions 6.0.1, 5.5.4, 5.4.4, 5.3.5, and possib...
CVE-2026-55669MEDIUM4.2ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Prov...
CVE-2026-55641HIGH8.29Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by re...
CVE-2026-55638HIGH8.69Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/da...
CVE-2026-54919HIGH7.4cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions ...
CVE-2026-54063HIGH7.5Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the checkSheet(...
CVE-2026-53657HIGH8.2Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to 2.1.3, on an instance of Lima...
CVE-2026-53653HIGH8.7Grav is a file-based Web platform. Prior to 1.7.53 and 2.0.0-rc.8, Grav allows an unauthenticated visitor to exhaust ser...
CVE-2026-51119CRITICAL9.1An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser co...
CVE-2026-3251MEDIUM6.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webremium Istanbul...
CVE-2026-39903HIGH7.1Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulne...
CVE-2026-39244HIGH7.5adm-zip before 0.5.18 is vulnerable to denial of service via a crafted ZIP file with a manipulated uncompressed size hea...
CVE-2026-2398HIGH8.8Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows Privil...
CVE-2026-1667HIGH7.2The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scrip...