CVE Vulnerability Database

Search and browse 376,679 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-68944Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67316. Reason: This candidate is a ...
CVE-2026-68943Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67314. Reason: This candidate is a ...
CVE-2026-68942Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67313. Reason: This candidate is a ...
CVE-2026-68941Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67312. Reason: This candidate is a ...
CVE-2026-68480In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust against interrupt in...
CVE-2026-67689CRITICAL9.8SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `or...
CVE-2026-67688CRITICAL9.8ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module....
CVE-2026-67687HIGH8.8Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/rol...
CVE-2026-67622CRITICAL9.9Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration th...
CVE-2026-67621HIGH7.6Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perf...
CVE-2026-67434HIGH7.3PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13....
CVE-2026-67422HIGH7.5pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, ...
CVE-2026-65400CRITICAL9.8An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS...
CVE-2026-64677MEDIUM5.9Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not ...
CVE-2026-64665HIGH8.1Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was ...
CVE-2026-64664MEDIUM4.3Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont...
CVE-2026-64663MEDIUM6.5Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-sup...
CVE-2026-64662MEDIUM6.5Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont...
CVE-2026-64655LOW2.1GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify  builds the certificate S...
CVE-2026-64654MEDIUM5.3GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed ex...
CVE-2026-64653MEDIUM5.1GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable pat...
CVE-2026-64652LOW3.3GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characte...
CVE-2026-63725HIGH8.6sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a ta...
CVE-2026-63637HIGH8.6Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter....
CVE-2026-62857HIGH8.8Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the...