CVE Vulnerability Database

Search and browse 390,041 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-59873HIGH7.5node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds...
CVE-2026-59871HIGH7.5node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and lin...
CVE-2026-59870HIGH7.5js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.1, YAML11_SCHEMA support for the !!omap tag in src...
CVE-2026-59869HIGH7.5js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend ...
CVE-2026-59868HIGH7.5js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.0, when merge keys are enabled, js-yaml can spend ...
CVE-2026-59725HIGH7.5Socket.IO enables bidirectional and low-latency communication for every platform. From 4.1.0 before 6.6.7, Engine.IO pro...
CVE-2026-59724HIGH7.5Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO ser...
CVE-2026-59702CRITICAL9.3repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated ...
CVE-2026-59262HIGH7.1AFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing a...
CVE-2026-57439MEDIUM5CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.2.0, the Series Chart opera...
CVE-2026-55761MEDIUM5.9Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t...
CVE-2026-54344HIGH8.8ToolJet is an open-source low-code platform for building internal tools. Prior to 3.20.180, ToolJet's render preview dep...
CVE-2026-53951HIGH8.8Copier is a library and CLI app for rendering project templates. In versions 9.5.0 through 9.15.1, the `trust` setting's...
CVE-2026-49946Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-49945Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-49944Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-3144CRITICAL9.8IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized ac...
CVE-2026-15063MEDIUM6.3A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication...
CVE-2026-14967LOW3.1BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory...
CVE-2026-14966LOW3.1BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it fa...
CVE-2026-59703HIGH8.7repomix contains a local file inclusion vulnerability in the git clone endpoint that allows unauthenticated attackers to...
CVE-2026-55874HIGH7.7SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in th...
CVE-2026-55873MEDIUM4.3SeaweedFS is a distributed storage system. In versions 4.08 through 4.33, requests signed with SigV4 service s3tables ar...
CVE-2026-55668MEDIUM6.3File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor ...
CVE-2026-54652HIGH8.1Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any aut...