CVE Vulnerability Database

Search and browse 394,249 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-47692MEDIUM4.3Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9...
CVE-2026-47221HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.18.0 until 1.35.13, 1.36.9...
CVE-2026-47207MEDIUM6.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9...
CVE-2026-47206LOW2.3Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.9, Dragonfly has a RESP Proto...
CVE-2026-47204HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.26.0 until 1.35.13, 1.36.9...
CVE-2026-33646CRITICAL9.6mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files ...
CVE-2026-57518HIGH8.8Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage ...
CVE-2026-57231HIGH7.5Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environ...
CVE-2026-56823MEDIUM5.4AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-56663HIGH8.5AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-55686MEDIUM5.3Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where...
CVE-2026-55677HIGH7.5Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decodi...
CVE-2026-54636CRITICAL9.9Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system...
CVE-2026-48529MEDIUM6GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mo...
CVE-2026-45408CRITICAL9Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell meta...
CVE-2026-45407MEDIUM5.5Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:auth command creates $DOKKU_ROOT/.netrc using bash's touch comm...
CVE-2026-45406HIGH8.8Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-i...
CVE-2026-45405HIGH8.8Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract user-supplied tar/z...
CVE-2026-28385MEDIUM5In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import funct...
CVE-2026-13434MEDIUM4.9A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multu...
CVE-2026-11779MEDIUM5.3An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the ac...
CVE-2025-32423MEDIUM5.3AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2025-32394MEDIUM5.3AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-9640HIGH7.2A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 reg...
CVE-2026-9639MEDIUM6.5Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticat...