CVE Vulnerability Database

Search and browse 394,518 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-61019HIGH7.5An issue in the sqlo_key_part_best component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial ...
CVE-2025-61018HIGH7.5An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial o...
CVE-2025-13162MEDIUM4.4Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master. This issue affect...
CVE-2026-56696MEDIUM5.4OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel sende...
CVE-2026-56695HIGH7.1OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote ...
CVE-2026-56694MEDIUM5.4NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where hand...
CVE-2026-56693MEDIUM5.5NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that pe...
CVE-2026-56692MEDIUM5.5NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controll...
CVE-2026-56402MEDIUM6.5NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails ...
CVE-2026-55767MEDIUM5.8Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain a...
CVE-2026-55766MEDIUM4.8guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject C...
CVE-2026-55568MEDIUM5.9Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by...
CVE-2026-54314HIGH7.5n8n is an open source workflow automation platform. Prior to 2.24.0, the Compression node's Decompress operation expande...
CVE-2026-54313HIGH7.7n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with workflow edit access cou...
CVE-2026-54312HIGH8.5n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with permission to create or ...
CVE-2026-54311HIGH7.7n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to...
CVE-2026-54310CRITICAL9.9n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to...
CVE-2026-54309CRITICAL10n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP tra...
CVE-2026-54303MEDIUM5.4n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Microsoft Teams trigger...
CVE-2026-52673MEDIUM6.5SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remote attacker to execute arbitrary code via the getD...
CVE-2025-62180HIGH7.1Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authentica...
CVE-2025-55639MEDIUM6.5GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomed...
CVE-2025-15619LOW3.5HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a sin...
CVE-2026-56815HIGH7.4pwnlift before d7a9544, in a privileged deployment, contains a symlink following vulnerability in the upload handler in ...
CVE-2026-35019CRITICAL9.2NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulnerability that allows ...