CVE Vulnerability Database

Search and browse 390,025 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-57020HIGH7.1An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper N...
CVE-2026-57019HIGH7.1An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Net...
CVE-2026-55689HIGH8.1OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skippe...
CVE-2026-55605MEDIUM5.3DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.8.0, the self-hos...
CVE-2026-55604HIGH8.6DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.7.0, the process-...
CVE-2026-55424MEDIUM5.4Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a topic "featured ...
CVE-2026-55170MEDIUM5.4OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, when MySQL is being used as the dat...
CVE-2026-53963CRITICAL9Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second...
CVE-2026-53962MEDIUM5.4Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG s...
CVE-2026-53961MEDIUM6.5Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the AWS SES bounce...
CVE-2026-49256HIGH7.5Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and...
CVE-2026-46413MEDIUM6.5Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, regular users coul...
CVE-2026-45788HIGH7.5Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, secure uploads cou...
CVE-2026-45780MEDIUM4.3Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, EventSerializer co...
CVE-2026-44787HIGH7.1Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow co...
CVE-2026-39246HIGH7.5decompress before 4.2.2 allows arbitrary symlink creation during archive extraction. When processing symlink entries (ty...
CVE-2026-39245MEDIUM6.2decompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file ...
CVE-2026-39243MEDIUM5.5decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and ...
CVE-2026-38076HIGH7.5An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Deni...
CVE-2026-33803MEDIUM6.9An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolve...
CVE-2026-33802MEDIUM6.8A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated...
CVE-2026-15276LOW3.3A flaw has been found in pdeljanov Symphonia up to 0.6.0. This vulnerability affects unknown code of the component Metad...
CVE-2026-15274LOW3.3A vulnerability was detected in lo48576 fbxcel up to 0.9.0. This affects an unknown part of the file src/pull_parser/v74...
CVE-2026-15271HIGH7.5A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 u...
CVE-2026-60120MEDIUM5.4Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows...