CVE Vulnerability Database

Search and browse 390,364 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-58176HIGH7.1RuoYi-Vue-Plus through 5.6.2, fixed in commit 88d03d9, exposes workflow task management endpoints under /workflow/task (...
CVE-2026-58174MEDIUM6.5Hermes WebUI before 0.51.521 validates the workspace of an imported session under the active named profile but construct...
CVE-2026-58173MEDIUM6.5Vibe-Trading before 0.1.10 contains a path traversal vulnerability that allows attackers to write files outside the inte...
CVE-2026-58172CRITICAL9.3Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denied clie...
CVE-2026-58171MEDIUM4.2Vibe-Trading before 0.1.10 constructs the swarm run directory by joining a caller-supplied run identifier onto the runs ...
CVE-2026-58170HIGH8.3Vibe-Trading before 0.1.10 builds the proposal file path by joining a caller-supplied proposal identifier onto the broke...
CVE-2026-58169HIGH7.7Vibe-Trading before 0.1.10 contains a DNS rebinding authentication bypass vulnerability that allows remote attackers to ...
CVE-2026-58168HIGH8.8DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke...
CVE-2026-58167HIGH7.1Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HT...
CVE-2026-58166CRITICAL9.1OpenBMB ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that allows unauthentica...
CVE-2026-58165HIGH8.8OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated...
CVE-2026-49451HIGH7.5The OpenAPI.NET SDK contains a useful object model for OpenAPI documents in .NET along with common serializers to extrac...
CVE-2026-10655MEDIUM5.9The asynchronous SNTP client in Zephyr (subsys/net/lib/sntp/sntp.c, sntp_close_async) closed the UDP socket file descrip...
CVE-2026-10654LOW3.1A race condition in the Zephyr Bluetooth Classic RFCOMM host stack (subsys/bluetooth/host/classic/rfcomm.c) mishandles a...
CVE-2026-10653HIGH8.1The Zephyr net_buf library (lib/net_buf/buf.c) manipulated both of its reference counts -- the per-header buf->ref and t...
CVE-2026-10652HIGH7.4Zephyr's DNS resolver (subsys/net/lib/dns) parses resource records from DNS responses in dns_unpack_answer(), which vali...
CVE-2026-48315CRITICAL9.3ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re...
CVE-2026-48314MEDIUM6.5ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir...
CVE-2026-48313CRITICAL9.3ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir...
CVE-2026-48307HIGH8.8ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An...
CVE-2026-48286CRITICAL10Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerabil...
CVE-2026-48285HIGH8.6ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that ...
CVE-2026-48283CRITICAL10ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulne...
CVE-2026-48282CRITICAL10ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir...
CVE-2026-48281CRITICAL10ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re...