CVE Vulnerability Database

Search and browse 390,049 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-55433MEDIUM5.4Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55432MEDIUM5.4Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55431MEDIUM6.1Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55430MEDIUM6.8Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55429HIGH8.7Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55428HIGH8.2Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55427HIGH8.3Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55079MEDIUM6.5Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.24.0 and pr...
CVE-2026-59705CRITICAL9.8mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers t...
CVE-2026-59704HIGH7.1Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metada...
CVE-2026-55078MEDIUM6.5Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.17.0 and pr...
CVE-2026-55077HIGH7.2Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55076HIGH7.4Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-51937HIGH7.5An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsAp...
CVE-2026-50811MEDIUM6.5An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736...
CVE-2026-50810MEDIUM5.5A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master HEAD before commit b35...
CVE-2026-37271CRITICAL9.8Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GA...
CVE-2026-37270CRITICAL9.8Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper passwor...
CVE-2026-36163MEDIUM5.4An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execut...
CVE-2026-36162MEDIUM5.4An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 all...
CVE-2026-14895HIGH7.5String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtri...
CVE-2026-14740CRITICAL9.1DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The pr...
CVE-2026-14739CRITICAL9.8DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeho...
CVE-2026-14380HIGH8.8DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is ass...
CVE-2026-59706CRITICAL9.3mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request f...