CVE Vulnerability Database

Search and browse 394,301 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-9099HIGH7.7A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin RE...
CVE-2026-9086HIGH7.3A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` ...
CVE-2026-9083MEDIUM4.9A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submi...
CVE-2026-56123CRITICAL9.8socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5...
CVE-2026-55439MEDIUM5.5Halo is an open source website building tool. Prior to 2.24.3, a path traversal vulnerability in the backup download end...
CVE-2026-55413CRITICAL9.4ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ...
CVE-2026-55412HIGH8.3ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ...
CVE-2026-55411MEDIUM6.8ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ...
CVE-2026-55092HIGH7.5Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image...
CVE-2026-54573MEDIUM5.3Outline is a service that allows for collaborative documentation. Prior to 1.8.0, the AuthenticationHelper.canAccess fun...
CVE-2026-54448MEDIUM6.5Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker read...
CVE-2026-54040HIGH7.1LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/auth/2fa/b...
CVE-2026-54037MEDIUM6.5LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2025-710...
CVE-2026-54033MEDIUM6.5LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, LibreChat allows users t...
CVE-2026-54030CRITICAL9.3LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.5, LibreChat's MCP OAuth implem...
CVE-2026-54029MEDIUM6.5LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages...
CVE-2026-54027MEDIUM6.5LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/imag...
CVE-2026-54025MEDIUM5.4LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, there is a vulnerability...
CVE-2026-54024MEDIUM6.5LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2024-111...
CVE-2026-45233HIGH8.1HTMLy CMS through 3.1.1 contains a path traversal vulnerability that allows low-privileged authenticated attackers to re...
CVE-2026-13351HIGH7.5Zephyr's IPv6 network stack can be prevented from receiving or processing future incoming packets by sending a small num...
CVE-2026-13350LOW2.3Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't b...
CVE-2026-9718MEDIUM6.5CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-servi...
CVE-2026-9717HIGH7.2CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could...
CVE-2026-9716HIGH7.5CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the devi...