CVE Vulnerability Database

Search and browse 392,294 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-53492CRITICAL9.6containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation impr...
CVE-2026-53489MEDIUM6.5containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plu...
CVE-2026-53467MEDIUM5.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-53466MEDIUM6.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-51947CRITICAL9.8An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 a...
CVE-2026-50195CRITICAL9.9containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the ...
CVE-2026-50160CRITICAL10Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and e...
CVE-2026-49119HIGH8.7Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that all...
CVE-2026-47262MEDIUM5.5containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vuln...
CVE-2026-41121HIGH7.8Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Before File Access ('Lin...
CVE-2026-38142MEDIUM6.5An unauthenticated command injection vulnerability in the /goform/fast_setting_internet_set endpoint of Tenda AC18 v15.0...
CVE-2026-14358MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun...
CVE-2026-13769MEDIUM6.8Overly permissive file permissions in AWS CLI before 1.44.78 (v1) and 2.34.29 (v2) on Unix-like systems where the umask ...
CVE-2026-13760HIGH7.3OS command injection in the NodejsFunction Docker bundling pipeline (OsCommand helper) in AWS aws-cdk-lib on all platfor...
CVE-2026-5051MEDIUM4.4HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin dire...
CVE-2026-58521CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foun...
CVE-2026-58520MEDIUM6.1URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener E...
CVE-2026-57737MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortco...
CVE-2026-57736HIGH7.4Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. Thi...
CVE-2026-57723HIGH7.4Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal....
CVE-2026-57722MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable ...
CVE-2026-54428HIGH7.5Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 an...
CVE-2026-51946MEDIUM6.5SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.2.26) allows a remote attacker to execute arbitrary...
CVE-2026-49091HIGH8Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forgin...
CVE-2026-49090MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (C...