CVE Vulnerability Database

Search and browse 394,408 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-48020CRITICAL10Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulner...
CVE-2026-45792MEDIUM5.5rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.32.0, RTK (Rust Token Killer) ...
CVE-2026-39253HIGH8.1An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll a...
CVE-2026-55736MEDIUM5.9Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a...
CVE-2026-55249HIGH8.8@rtk-ai/rtk-rewrite transparently rewrites shell commands executed via OpenClaw's exec tool to their RTK equivalents. In...
CVE-2026-54322HIGH7.7Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1...
CVE-2026-54321HIGH7Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. From 0.101.0...
CVE-2026-54320HIGH8.4Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1...
CVE-2026-54319MEDIUM4.2Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1...
CVE-2026-53755HIGH7.5Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.9, the Docker API server applied its SSRF de...
CVE-2026-53754HIGH7.5Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.8, the Docker API server's SSRF protection (...
CVE-2026-53753CRITICAL10Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in t...
CVE-2026-57062LOW2.9CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM becaus...
CVE-2026-57053LOW2.5GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandl...
CVE-2026-55517MEDIUM4.3Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.5, a Deno program that opens a client WebSocket ...
CVE-2026-54324MEDIUM6.5Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1...
CVE-2026-54323MEDIUM5.9Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1...
CVE-2026-54318HIGH7.1Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the...
CVE-2026-54317HIGH7.6Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the...
CVE-2026-54316CRITICAL9.1Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved ...
CVE-2026-54257CRITICAL9.3Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.1 unti...
CVE-2026-54157CRITICAL9LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to ...
CVE-2026-54022MEDIUM5.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the ...
CVE-2026-54021MEDIUM6.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, sever...
CVE-2026-54019MEDIUM6.5Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open ...