CVE Vulnerability Database

Search and browse 390,126 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-54887MEDIUM4.8Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl (DTLS server) allows predictable DTLS cookie computatio...
CVE-2026-54886MEDIUM4.3Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an auth...
CVE-2026-53422MEDIUM4.3Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to ...
CVE-2026-50282MEDIUM4.9Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and...
CVE-2026-50281HIGH7.1Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a mass-assignment flaw...
CVE-2026-44935CRITICAL9.9Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.1...
CVE-2024-58352HIGH8.7Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attackers to query arbitr...
CVE-2024-14037CRITICAL9.8Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote...
CVE-2022-50973CRITICAL9.8Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servl...
CVE-2026-58455CRITICAL9.8Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to...
CVE-2026-44941HIGH8.8A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attack...
CVE-2026-9272HIGH8.1In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenti...
CVE-2026-8079HIGH7.3In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged...
CVE-2026-56842HIGH7.5A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulne...
CVE-2026-56841HIGH8.8A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerabili...
CVE-2026-56004CRITICAL10A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by ...
CVE-2026-55119HIGH8.1A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f...
CVE-2026-55118HIGH8.3A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Acces...
CVE-2026-55117HIGH8.6A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Applicat...
CVE-2026-55116CRITICAL9.8A malicious actor with access to the network and under certain network configurations could exploit an Improper Access C...
CVE-2026-55115CRITICAL9.9A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in Un...
CVE-2026-55114HIGH8.8A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f...
CVE-2026-55113HIGH7.5A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in U...
CVE-2026-55112HIGH8.8A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper A...
CVE-2026-55111HIGH7.5A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Protect Floodli...