CVE Vulnerability Database

Search and browse 394,365 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-47267HIGH8.3Gogs is an open source self-hosted Git service. Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or ru...
CVE-2026-46423CRITICAL9.3Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, ...
CVE-2026-45757LOW2.3Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, ...
CVE-2026-45689CRITICAL9.1Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, ...
CVE-2026-45688CRITICAL9.1Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, ...
CVE-2026-45687HIGH8.5Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, ...
CVE-2026-45677HIGH8.7Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, ...
CVE-2026-33543CRITICAL9.3FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API end...
CVE-2026-33235HIGH7.7AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-32315MEDIUM5.5motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Version...
CVE-2026-31978MEDIUM6.5motionEye (mEye) is an online interface for motion software, which is a video surveillance program with motion detection...
CVE-2026-25119HIGH7.7Gogs is an open source self-hosted Git service. Prior to 0.14.3, when ENABLE_REVERSE_PROXY_AUTHENTICATION is enabled, Go...
CVE-2026-1840HIGH8.7The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication contr...
CVE-2026-13208MEDIUM6.5A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SE...
CVE-2026-13201HIGH7.3A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW...
CVE-2026-11998HIGH7.6A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and ...
CVE-2025-64719MEDIUM4.9Gogs is an open source self-hosted Git service. Prior to 0.14.3, a malicious user with rights to create a new file on a ...
CVE-2026-55583HIGH7.6Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.9.0, Twenty was vulnerable to a cro...
CVE-2026-48028MEDIUM6.5Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodo...
CVE-2026-47389HIGH8.6Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, when us...
CVE-2026-46349MEDIUM5.3Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodo...
CVE-2026-46348HIGH8.7Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, the lis...
CVE-2026-27708HIGH7.1FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom ...
CVE-2026-23879HIGH8py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryptio...
CVE-2026-53950HIGH7.5@tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulne...