CVE Vulnerability Database

Search and browse 394,050 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-56278CRITICAL9.3Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the exp...
CVE-2026-56277MEDIUM6.5Flowise before 3.1.2 sets Access-Control-Allow-Origin to a hardcoded wildcard (*) on its text-to-speech (TTS) generation...
CVE-2026-56264MEDIUM6.1Crawl4AI before 0.8.7 contains an arbitrary JavaScript execution vulnerability in the Docker API server's /execute_js en...
CVE-2026-56249HIGH7.6Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation endpoint that allows authen...
CVE-2026-56247HIGH8.8Capgo before 12.128.2 allows org admins to assign org-scoped RBAC roles at app scope without validating role scope compa...
CVE-2026-56233HIGH8.7Capgo before 12.128.2 contains a path traversal vulnerability in the builder upload proxy that allows authenticated user...
CVE-2026-56230HIGH8.8Capgo before 12.128.2 contains a broken object level authorization vulnerability in middlewareKey() that accepts the cli...
CVE-2026-56224MEDIUM5.4Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query parameters, automatica...
CVE-2026-56219HIGH8.7Capgo before 12.128.2 contains a NULL-auth bypass vulnerability in the public.get_org_user_access_rbac function that all...
CVE-2026-55721CRITICAL9.3Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debu...
CVE-2026-55223MEDIUM6.3c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can c...
CVE-2026-54696LOW3.7Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2.19.8 are vulnerable to heap buffer overflow when t...
CVE-2026-54673MEDIUM6.5electron-updater allows for automatic updates for Electron apps. Prior to 9.7.0, the HTTP redirect handler (HttpExecutor...
CVE-2026-54672HIGH7.8electron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder...
CVE-2026-52198HIGH7.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-52197HIGH7.5An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead...
CVE-2026-52195HIGH7.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-52193HIGH7.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-50110CRITICAL9.3Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configu...
CVE-2026-50040MEDIUM6.1Storage Concentrator (SC & SCVM) is vulnerable to reflected cross-site scripting due to unsanitized content being echoed...
CVE-2026-28322MEDIUM5.6SolarWinds Database Performance Analyzer was found to be affected by a stored cross-site scripting vulnerability, which ...
CVE-2026-14156MEDIUM6.5Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker wh...
CVE-2026-14155MEDIUM6.5Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to...
CVE-2026-14154MEDIUM4.8Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a use...
CVE-2026-14153MEDIUM5.3Inappropriate implementation in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a u...