CVE Vulnerability Database

Search and browse 394,712 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-45480CRITICAL10Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-42895HIGH7.5Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut...
CVE-2026-32208MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an aut...
CVE-2026-49345MEDIUM5.3Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, ...
CVE-2026-49344HIGH7.1Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, ...
CVE-2026-49342MEDIUM5.3YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache ...
CVE-2026-48787HIGH7.4gin-vue-admin is an AI-assisted basic development platform. In version 2.9.1, an authenticated attacker with access to t...
CVE-2026-48774HIGH7.5ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 3.0.0 through 3.0.8, ProxySQL's GenAI/MC...
CVE-2026-48773CRITICAL9.8ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authenticat...
CVE-2026-48772CRITICAL10ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL ...
CVE-2026-48715HIGH8.8radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contai...
CVE-2026-48089HIGH7.1DevGuard provides vulnerability management for the full software supply chain. Prior to 1.4.2, on a DevGuard API instanc...
CVE-2026-9375Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-49340HIGH8.1gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic e...
CVE-2026-49339HIGH7.1gonic is a music streaming server / free-software subsonic server API implementation. The maintainer's fix in commit `6...
CVE-2026-49338HIGH7.1gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subso...
CVE-2026-49336MEDIUM5.5@microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-prev...
CVE-2026-49293HIGH7.5js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. Versions up to and including 1.1.0 pa...
CVE-2026-49291HIGH8.1mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpo...
CVE-2026-49288MEDIUM4.3Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, an authenticated Con...
CVE-2026-27878MEDIUM6.5A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive...
CVE-2026-12726MEDIUM6.3A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller sto...
CVE-2026-12238MEDIUM5.3The WP Go Maps – Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up t...
CVE-2023-54357HIGH7.5Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attacker...
CVE-2026-49359MEDIUM6.5PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/...