CVE Vulnerability Database
Search and browse 394,279 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9800 | HIGH | 8.1 | 0.6% | Jun 25, 2026 | A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorizati... |
| CVE-2026-9799 | MEDIUM | 4.6 | 0.2% | Jun 25, 2026 | A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permissio... |
| CVE-2026-9705 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registrati... |
| CVE-2026-9099 | HIGH | 7.7 | 0.3% | Jun 25, 2026 | A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin RE... |
| CVE-2026-9086 | HIGH | 7.3 | 0.4% | Jun 25, 2026 | A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` ... |
| CVE-2026-9083 | MEDIUM | 4.9 | 0.5% | Jun 25, 2026 | A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submi... |
| CVE-2026-56123 | CRITICAL | 9.8 | 0.3% | Jun 25, 2026 | socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5... |
| CVE-2026-55439 | MEDIUM | 5.5 | 0.3% | Jun 25, 2026 | Halo is an open source website building tool. Prior to 2.24.3, a path traversal vulnerability in the backup download end... |
| CVE-2026-55413 | CRITICAL | 9.4 | 0.3% | Jun 25, 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ... |
| CVE-2026-55412 | HIGH | 8.3 | 0.2% | Jun 25, 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ... |
| CVE-2026-55411 | MEDIUM | 6.8 | 0.1% | Jun 25, 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ... |
| CVE-2026-55092 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image... |
| CVE-2026-54573 | MEDIUM | 5.3 | 0.3% | Jun 25, 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.8.0, the AuthenticationHelper.canAccess fun... |
| CVE-2026-54448 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker read... |
| CVE-2026-54040 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/auth/2fa/b... |
| CVE-2026-54037 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2025-710... |
| CVE-2026-54033 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, LibreChat allows users t... |
| CVE-2026-54030 | CRITICAL | 9.3 | 0.1% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.5, LibreChat's MCP OAuth implem... |
| CVE-2026-54029 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages... |
| CVE-2026-54027 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/imag... |
| CVE-2026-54025 | MEDIUM | 5.4 | 0.1% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, there is a vulnerability... |
| CVE-2026-54024 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2024-111... |
| CVE-2026-45233 | HIGH | 8.1 | 0.6% | Jun 25, 2026 | HTMLy CMS through 3.1.1 contains a path traversal vulnerability that allows low-privileged authenticated attackers to re... |
| CVE-2026-13351 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | Zephyr's IPv6 network stack can be prevented from receiving or processing future incoming packets by sending a small num... |
| CVE-2026-13350 | LOW | 2.3 | 0.2% | Jun 25, 2026 | Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't b... |
