CVE Vulnerability Database

Search and browse 390,049 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-59153LOW2.1Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve me...
CVE-2026-58266MEDIUM6.5Anki is a program for creating and reviewing flashcards. Prior to 25.09.4, Anki's webview-based pages communicate with t...
CVE-2026-55490MEDIUM6.5OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a()...
CVE-2026-55418HIGH8.6FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file handlers authorize an unr...
CVE-2026-55408HIGH8.4Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution throu...
CVE-2026-55075HIGH7.4Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-54698MEDIUM5.9Hasura is an open-source product that provides users GraphQL or REST APIs. Prior to 2.49.2 and 2.45.5, a user can use a ...
CVE-2026-54607HIGH7.7FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta4, the HTTP-tool OpenAPI schema importer valid...
CVE-2026-54602HIGH7.1FastGPT is a knowledge-based AI application platform. Prior to 4.15.0, GET /api/core/ai/record/getRecord authenticates t...
CVE-2026-54601MEDIUM6.3FastGPT is an open source AI knowledge base platform. From 4.14.17 to before 4.15.0-beta4, FastGPT allows an authenticat...
CVE-2026-50179MEDIUM4.2Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/s...
CVE-2026-49229HIGH8.3Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks f...
CVE-2026-49033HIGH8.4The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arb...
CVE-2026-46354CRITICAL9.1Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29...
CVE-2026-45796MEDIUM6.5Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13...
CVE-2026-42958HIGH8.4The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing s...
CVE-2026-42953HIGH8.4The application contains an out-of-bounds write vulnerability that can be exploited by an attacker to cause the program ...
CVE-2026-28378LOW2.7The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organizatio...
CVE-2026-59707CRITICAL9.2LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that al...
CVE-2026-58583HIGH8.4FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege esc...
CVE-2026-58473CRITICAL9.3Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite...
CVE-2026-58472HIGH7.1GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string...
CVE-2026-58471HIGH7.1GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() f...
CVE-2026-58470MEDIUM6.9GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range(...
CVE-2026-58469HIGH8.7GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_s...