CVE Vulnerability Database

Search and browse 390,029 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-13461CRITICAL9.6When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 ...
CVE-2026-61474MEDIUM5.3An improper authorization check in MISP’s attribute creation endpoint allowed an authenticated user with permission to a...
CVE-2026-59208MEDIUM6.8n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances confi...
CVE-2026-59207MEDIUM6.5n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce th...
CVE-2026-59206HIGH7.1n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with t...
CVE-2026-58125Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-42486CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-23562CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-23561CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-23560CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-23559CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-23556CRITICAL9.4When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ...
CVE-2026-15189MEDIUM6.3A security vulnerability has been detected in aerostackdev aerostack-mcp up to 6315dfde7df0a15aaf743f88d91347115e09ba23....
CVE-2026-15188MEDIUM6.3A weakness has been identified in manjurulhoque django-job-portal up to dfa352f305bba44445ac5dc12e9b2a98c9dcd71f. Affect...
CVE-2026-15187MEDIUM4.3A security flaw has been discovered in enquirer up to 2.4.1. Affected is the function Enquirer.set of the component Publ...
CVE-2026-11404HIGH7.5Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello...
CVE-2025-58151CRITICAL9.4varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF ...
CVE-2025-58146CRITICAL9.4There are multiple issues. 1. Updates to the XAPI database sanitise input strings, but try generating the notifica...
CVE-2025-27464CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-27463CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-27462CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-60109HIGH8.7Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol analyzer that allows unauth...
CVE-2026-60108HIGH8.7Zeek before 8.0.9 contains an uncontrolled memory consumption vulnerability in the FTP analyzer that allows unauthentica...
CVE-2026-5005MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics...
CVE-2026-56292HIGH7.5Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 10.11.1 - A SQLi vulnerability in AcyMailing...