CVE Vulnerability Database

Search and browse 394,249 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-44735MEDIUM6.5OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the GET /api/v3/shares en...
CVE-2026-44734MEDIUM6.5OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization v...
CVE-2026-44733MEDIUM5.9OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, Business Logic Error on O...
CVE-2026-44732MEDIUM4.3OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, OpenProject exposes a doc...
CVE-2026-44731MEDIUM4.3OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the web application's mee...
CVE-2026-44696MEDIUM5.7OpenProject is open-source, web-based project management software. Prior to 17.4.0, OpenProject's rich text (markdown) r...
CVE-2026-32833HIGH8.8Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authe...
CVE-2026-29509MEDIUM5.4Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfi...
CVE-2026-54753MEDIUM5.9Nx is a monorepo solution for TypeScript and polyglot codebases. From 17.0.4 until 22.7.2 and 23.0.0-beta.2, the local H...
CVE-2026-48090MEDIUM5.9Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38...
CVE-2026-47220HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38...
CVE-2026-47205MEDIUM5.9Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.36.0 until 1.36.9, 1.37.5,...
CVE-2026-13372HIGH7.2Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026...
CVE-2026-56876HIGH8.6extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file contain...
CVE-2026-55448MEDIUM6.3mise manages dev tools like node, python, cmake, and terraform. From 2026.3.15 until 2026.6.4, mise loads github.credent...
CVE-2026-55441HIGH8.6mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config fil...
CVE-2026-54557MEDIUM5.5mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its inst...
CVE-2026-54341HIGH7.5Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.0, a crafted RESTORE payload ...
CVE-2026-48743HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,...
CVE-2026-48706HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9...
CVE-2026-48497HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,...
CVE-2026-48044HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.23.0 until 1.35.11, 1.36.7...
CVE-2026-48042HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,...
CVE-2026-47778MEDIUM4.4Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,...
CVE-2026-47775MEDIUM6.8Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,...