CVE Vulnerability Database

Search and browse 390,072 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-53644HIGH8.6FOSSBilling is a free, open-source billing and client management system. Versions 0.5.3 through 0.7.2 allow authenticate...
CVE-2026-53643HIGH8.7FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged st...
CVE-2026-53642MEDIUM5.3FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when the "Requ...
CVE-2026-53641MEDIUM4.8FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a stored cros...
CVE-2026-53640LOW2.3FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, low-privileged staff ac...
CVE-2026-59710MEDIUM6.1showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/ta...
CVE-2026-43928LOW2.3FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the PayPalEmail payment...
CVE-2026-43927MEDIUM6.9FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, a race condition in the...
CVE-2026-43925MEDIUM6.9FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, an unauthenticated mass...
CVE-2026-43921HIGH8.9FOSSBilling is a free, open-source billing and client management system. Versions 0.6.10 through 0.7.2 have a PHP code i...
CVE-2026-43918HIGH8.7FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, when a client or staff/...
CVE-2026-42204HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.471 ...
CVE-2026-42153HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-42148LOW3.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-41899MEDIUM6.5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-38979MEDIUM5.4ajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI. In ajenti-core/aj/...
CVE-2026-38976HIGH7.5mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/vm.c in op_super() / OP_SUPER due to a missi...
CVE-2026-38973MEDIUM4.4mrubyc through release3.4.1 was found to contain an out-of-bounds read in builtin missing-method lookup inside mrbc_find...
CVE-2026-34599HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34167MEDIUM5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34153HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34050MEDIUM6.5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34049LOW3.3Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.451 ...
CVE-2026-32718MEDIUM6.5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-59713HIGH8.6Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without...