CVE Vulnerability Database

Search and browse 390,072 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-59712HIGH8.6Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to ...
CVE-2026-59711MEDIUM6.1showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitr...
CVE-2026-57573HIGH8.6Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF ...
CVE-2026-57572CRITICAL10Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-...
CVE-2026-57571CRITICAL9.6Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded fil...
CVE-2026-55727HIGH7.5A flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14...
CVE-2026-55574HIGH7.5vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_ou...
CVE-2026-55514MEDIUM6.5vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a...
CVE-2026-54765HIGH8.5Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gatewa...
CVE-2026-54764MEDIUM5.8Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middle...
CVE-2026-54763CRITICAL10Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestA...
CVE-2026-54709Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-54637. Reason: This candidate is a ...
CVE-2026-54234HIGH7.5vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal ...
CVE-2026-50135MEDIUM5.5Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made  RootMappingFs.statRoot  use  Stat  (follows...
CVE-2026-48267MEDIUM5.5DNG SDK versions 1.7.1 2536 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an...
CVE-2026-42341CRITICAL9.2FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenti...
CVE-2026-42331HIGH7.7FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/u...
CVE-2026-34038CRITICAL9.9Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-33734MEDIUM6.9FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a SQL injecti...
CVE-2026-25271HIGH7Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between chec...
CVE-2026-25268HIGH8.8Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
CVE-2026-21384MEDIUM5.3Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported ...
CVE-2026-21383HIGH7.1Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value fo...
CVE-2026-21379HIGH7.8Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
CVE-2026-21370MEDIUM5.3Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.