CVE Vulnerability Database

Search and browse 394,613 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-56382HIGH8.6Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability ...
CVE-2026-56381MEDIUM4.8Craft CMS from version 5.0.0-RC1 contains a stored cross-site scripting vulnerability in the User Permissions page where...
CVE-2026-56378HIGH8.2ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage...
CVE-2026-56367CRITICAL9.1ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding pat...
CVE-2026-56316MEDIUM6.9Cap-go before 12.128.2 contains an information disclosure vulnerability in the OPTIONS /build/upload/:jobId/* endpoint t...
CVE-2026-56299MEDIUM6.9Capgo before 12.128.2 contains an authentication bypass vulnerability in the /build/upload/:jobId/* endpoint that allows...
CVE-2026-56265CRITICAL9.8Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the ...
CVE-2026-56253HIGH8.7Capgo before 12.128.2 contains an improper access control vulnerability in the public.get_org_members RPC function that ...
CVE-2026-56251HIGH7Capgo before 12.128.2 contains a broken row level security policy in the org_users table that allows authenticated users...
CVE-2026-56242HIGH8.7Capgo before 12.128.2 contains an unauthenticated security definer RPC function get_identity_apikey_only that returns th...
CVE-2026-56239HIGH7.6Capgo before 12.128.2 contains a potential privilege escalation vulnerability in the public.apply_usage_overage SECURITY...
CVE-2026-56236MEDIUM6.8Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build credentials operations th...
CVE-2026-56229HIGH7.1Capgo before 12.128.2 contains an authorization bypass vulnerability in the /build/status and /build/logs endpoints that...
CVE-2025-71378HIGH7.8picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attacker...
CVE-2025-71357HIGH7.8picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in ...
CVE-2025-71351HIGH7.6picklescan before 0.0.25 fails to detect malicious pickle files that use timeit.timeit() in the __reduce__ method, allow...
CVE-2025-71348HIGH7.8picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config funct...
CVE-2026-12799MEDIUM4.3A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_vi...
CVE-2026-12798MEDIUM6.3A weakness has been identified in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function load_open...
CVE-2026-12797MEDIUM6.3A security flaw has been discovered in BerriAI litellm up to 1.82.5. Affected is the function async_pre_call_hook of the...
CVE-2026-12796MEDIUM6.3A vulnerability was identified in BerriAI litellm up to 1.82.2. This impacts the function get_redirect_response_from_ope...
CVE-2026-12795HIGH7.3A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm...
CVE-2026-12789MEDIUM4.7A vulnerability was identified in ILIAS Learning Management System 11.0. This issue affects the function ilTrQuery::exec...
CVE-2026-12788MEDIUM6.3A vulnerability was determined in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This vulnerabi...
CVE-2026-12787MEDIUM6.3A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This affects an unk...