CVE Vulnerability Database

Search and browse 376,679 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-48071MEDIUM5.8OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48054HIGH8.8OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin ...
CVE-2026-47765HIGH7.1Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints ...
CVE-2026-47194HIGH8.6Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic login link generation c...
CVE-2026-47185MEDIUM5.1Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspac...
CVE-2026-45573MEDIUM6.4Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-45572MEDIUM4.8Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-45415MEDIUM6Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-45414HIGH8.5Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API auth...
CVE-2026-45378HIGH7.5Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-43632CRITICAL9.2llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six to...
CVE-2026-43631CRITICAL9.2llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-se...
CVE-2026-43630MEDIUM6.5llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore p...
CVE-2026-43629CRITICAL9.2llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path whe...
CVE-2026-43628HIGH8.5llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sample...
CVE-2026-43627HIGH8.5llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where ...
CVE-2026-41861MEDIUM4.2Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with ...
CVE-2026-3418CRITICAL9.1The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or desti...
CVE-2026-3415HIGH8.7The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validatio...
CVE-2026-33181Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-33942. Reason: This candidate is a ...
CVE-2026-1289HIGH7.8A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A maliciou...
CVE-2026-19177HIGH8.3Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who ...
CVE-2026-19176HIGH7.5Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the render...
CVE-2026-19175CRITICAL9.6Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a s...
CVE-2026-19174HIGH8.8Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code insi...