CVE Vulnerability Database

Search and browse 394,603 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2023-33854MEDIUM5.3IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow a...
CVE-2026-9162MEDIUM4.3Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to invalidate cached ...
CVE-2026-9029MEDIUM5.4A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer ...
CVE-2026-8074LOW3.8Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user act...
CVE-2026-7167MEDIUM6.9The vulnerability arises when the system fails to properly validate the 'email' field during the authentication process,...
CVE-2026-7166CRITICAL9.2Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and p...
CVE-2026-7165CRITICAL9.4The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters a...
CVE-2026-6673MEDIUM6.4Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to authenticate Atlas...
CVE-2026-6653CRITICAL9.8Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker ...
CVE-2026-6062MEDIUM6.4Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 Fail to validate channel o...
CVE-2026-5139MEDIUM5.4Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to enforce administra...
CVE-2026-56450MEDIUM5.1AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reac...
CVE-2026-56448HIGH8.3A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e4...
CVE-2026-56447HIGH7.2MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path...
CVE-2026-56446HIGH7.2MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool...
CVE-2026-56425HIGH8.8The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorizat...
CVE-2026-56424HIGH8.8MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong ent...
CVE-2026-56423HIGH8.8MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The af...
CVE-2026-54100HIGH8.3A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishe...
CVE-2026-54099HIGH8.8A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR au...
CVE-2026-42129HIGH7.7A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endp...
CVE-2026-28381HIGH8.1The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the da...
CVE-2026-12888LOW2An HTML injection vulnerability exists in the Google Chat webhook notification  sent by Thinkst Applied Research Canaryt...
CVE-2026-12602HIGH8.8Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assig...
CVE-2026-10601MEDIUM4.3A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach uni...