CVE Vulnerability Database

Search and browse 390,364 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-48277CRITICAL10ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re...
CVE-2026-48276CRITICAL10ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulne...
CVE-2026-44948MEDIUM5.3A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up...
CVE-2026-13455MEDIUM4.3PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() ...
CVE-2026-4360MEDIUM5.3In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected sy...
CVE-2026-48192MEDIUM6.8A vulnerability has been identified in Mendix Studio Pro 10.11 (All versions), Mendix Studio Pro 10.12 (All versions), M...
CVE-2026-44949HIGH7A Rancher FleetWorkspace admission path allowed side effects to occur in the Rancher webhook handler for versions 0.7.0...
CVE-2026-44947MEDIUM6.9A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13....
CVE-2026-27957HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-27956MEDIUM4.3Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-27955MEDIUM6.6Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-27883MEDIUM5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-27882MEDIUM4.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-27881MEDIUM5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-35098MEDIUM6.9KTM System e-BOK does not implement any limit or timeout on consecutive login attempts, allowing an attacker to perform ...
CVE-2026-35097MEDIUM6.9KTM System e-BOK enforces a maximum password length of six numeric digits and does not permit the use of any alphabetic,...
CVE-2026-35096MEDIUM5.1KTM System e-BOK is vulnerable to Cross‑Site Request Forgery (CSRF) in both the email-change and password-change functio...
CVE-2026-35095MEDIUM4.8KTM System e-BOK allows the session identifier to be set by the client prior to authentication. If a cookie with a valid...
CVE-2026-14241CRITICAL9.8Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume th...
CVE-2026-14178MEDIUM5.9openGauss 在处理带 NLS 参数的 to_timestamp 调用时,to_timestamp_with_fmt_nls() 会将 nls_fmt_str 保存到 u_sess->parser_cxt.nls_fmt_str。在 ...
CVE-2025-53648MEDIUM5.4SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate fi...
CVE-2026-8655CRITICAL9.8Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous be...
CVE-2026-8452CRITICAL9.8Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Den...
CVE-2026-8451HIGH7.5Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetS...
CVE-2026-8403MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Eksagate Electroni...