CVE Vulnerability Database
Search and browse 394,249 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47692 | MEDIUM | 4.3 | 0.2% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9... |
| CVE-2026-47221 | HIGH | 7.5 | 0.4% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.18.0 until 1.35.13, 1.36.9... |
| CVE-2026-47207 | MEDIUM | 6.5 | 0.4% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9... |
| CVE-2026-47206 | LOW | 2.3 | — | Jun 26, 2026 | Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.9, Dragonfly has a RESP Proto... |
| CVE-2026-47204 | HIGH | 7.5 | 0.4% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.26.0 until 1.35.13, 1.36.9... |
| CVE-2026-33646 | CRITICAL | 9.6 | 0.7% | Jun 26, 2026 | mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files ... |
| CVE-2026-57518 | HIGH | 8.8 | 0.5% | Jun 26, 2026 | Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage ... |
| CVE-2026-57231 | HIGH | 7.5 | 0.3% | Jun 26, 2026 | Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environ... |
| CVE-2026-56823 | MEDIUM | 5.4 | — | Jun 26, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2026-56663 | HIGH | 8.5 | — | Jun 26, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2026-55686 | MEDIUM | 5.3 | — | Jun 26, 2026 | Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where... |
| CVE-2026-55677 | HIGH | 7.5 | — | Jun 26, 2026 | Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decodi... |
| CVE-2026-54636 | CRITICAL | 9.9 | 0.3% | Jun 26, 2026 | Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system... |
| CVE-2026-48529 | MEDIUM | 6 | — | Jun 26, 2026 | GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mo... |
| CVE-2026-45408 | CRITICAL | 9 | — | Jun 26, 2026 | Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell meta... |
| CVE-2026-45407 | MEDIUM | 5.5 | — | Jun 26, 2026 | Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:auth command creates $DOKKU_ROOT/.netrc using bash's touch comm... |
| CVE-2026-45406 | HIGH | 8.8 | — | Jun 26, 2026 | Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-i... |
| CVE-2026-45405 | HIGH | 8.8 | — | Jun 26, 2026 | Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract user-supplied tar/z... |
| CVE-2026-28385 | MEDIUM | 5 | 0.2% | Jun 26, 2026 | In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import funct... |
| CVE-2026-13434 | MEDIUM | 4.9 | 0.2% | Jun 26, 2026 | A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multu... |
| CVE-2026-11779 | MEDIUM | 5.3 | — | Jun 26, 2026 | An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the ac... |
| CVE-2025-32423 | MEDIUM | 5.3 | 0.2% | Jun 26, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2025-32394 | MEDIUM | 5.3 | — | Jun 26, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2026-9640 | HIGH | 7.2 | 0.3% | Jun 26, 2026 | A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 reg... |
| CVE-2026-9639 | MEDIUM | 6.5 | 0.4% | Jun 26, 2026 | Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticat... |
