CVE Vulnerability Database

Search and browse 390,117 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-59092CRITICAL9.8JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthentica...
CVE-2026-58580MEDIUM6LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. ...
CVE-2026-58579MEDIUM5.4RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalize...
CVE-2026-58578HIGH7.1LobeChat before version 2.2.10-canary.15 contains a regular expression denial of service (ReDoS) vulnerability that allo...
CVE-2026-58467HIGH8.2Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated ...
CVE-2026-58466CRITICAL9.8AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers t...
CVE-2026-58381MEDIUM6.1A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function whe...
CVE-2026-52187HIGH7.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2025-71385MEDIUM6.1Netdata before 2.3.1 reflects the user-supplied love query parameter of the api/v2/ilove.svg and api/v3/ilove.svg endpoi...
CVE-2026-7311HIGH8.1The TinyPNG – JPEG, PNG & WebP image compression plugin for WordPress is vulnerable to arbitrary file deletion due to in...
CVE-2026-58465HIGH8.7Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in the CoAP Block1 hand...
CVE-2026-13743LOW3.3CubeSpace CW0057 Reaction Wheel firmware versions prior to 5.0.20 are vulnerable to an Improper Verification of Cryptogr...
CVE-2026-8699HIGH7A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5...
CVE-2026-55952HIGH7.5The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientH...
CVE-2026-55950MEDIUM5.9Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an u...
CVE-2026-54891LOW3.7Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Erlang/OTP ssl...
CVE-2026-54887MEDIUM4.8Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl (DTLS server) allows predictable DTLS cookie computatio...
CVE-2026-54886MEDIUM4.3Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an auth...
CVE-2026-53422MEDIUM4.3Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to ...
CVE-2026-50282MEDIUM4.9Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and...
CVE-2026-50281HIGH7.1Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a mass-assignment flaw...
CVE-2026-44935CRITICAL9.9Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.1...
CVE-2024-58352HIGH8.7Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attackers to query arbitr...
CVE-2024-14037CRITICAL9.8Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote...
CVE-2022-50973CRITICAL9.8Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servl...