CVE Vulnerability Database

Search and browse 390,057 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-46700MEDIUM4.3Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-serve...
CVE-2026-46672MEDIUM4.6Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in pac...
CVE-2026-44454HIGH8.8Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30...
CVE-2026-58468MEDIUM5.5NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows au...
CVE-2026-44877MEDIUM6.5An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960...
CVE-2026-7017HIGH7.1HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server ...
CVE-2026-59800CRITICAL9.89Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-i...
CVE-2026-59708HIGH8.7The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeU...
CVE-2026-55435MEDIUM5.4Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and pr...
CVE-2026-48958HIGH8.8An improper access check allows unauthorized users to create custom fields via webservices endpoints.
CVE-2026-48957HIGH8.8An improper access check allows unauthorized users to access com_privacy datasets.
CVE-2026-48956MEDIUM5An improper access check allows users to display a list of modules in the frontend.
CVE-2026-48955MEDIUM6.5An improper access check allows unauthorized users to access workflow stage and transition information.
CVE-2026-48954MEDIUM6.1Improper validation leads to a generic XSS vector in the language override feature.
CVE-2026-48953MEDIUM6.1Lack of escaping leads to an XSS vulnerability in the generic image output layout.
CVE-2026-48952MEDIUM6.1Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
CVE-2026-48951MEDIUM6.1Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
CVE-2026-48950MEDIUM6.1Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
CVE-2026-48949MEDIUM6.1Lack of validation leads to an XSS vulnerability in the MFA management views.
CVE-2026-48948HIGH8.8An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
CVE-2026-48947MEDIUM4.9An improper access check allows privileged users to overwrite media files without editing permissions.
CVE-2026-57851HIGH8.5MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allo...
CVE-2026-23698HIGH8.6Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import featur...
CVE-2026-23697HIGH8.8Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve ...
CVE-2026-14904HIGH7.1AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create an...