CVE Vulnerability Database

Search and browse 394,846 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-52719HIGH7.1An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser rea...
CVE-2026-52718MEDIUM6.5A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse...
CVE-2026-50892MEDIUM6.5Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows auth...
CVE-2026-50891HIGH8.1Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges ...
CVE-2026-50890CRITICAL9.8Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /sto...
CVE-2026-50889HIGH7.5An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (...
CVE-2026-50888HIGH8.1An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillec...
CVE-2026-50887CRITICAL9.1A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attac...
CVE-2026-50886CRITICAL9.1Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan inte...
CVE-2026-50885HIGH7.5Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to...
CVE-2026-50884HIGH8.8Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administrator and access sens...
CVE-2026-50883CRITICAL9.6An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute ...
CVE-2026-50882HIGH7.5An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS)...
CVE-2026-50881HIGH8.1Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate p...
CVE-2026-50880CRITICAL9.8An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary cod...
CVE-2026-50879HIGH7.5An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Ser...
CVE-2026-50878HIGH7.5An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Serv...
CVE-2026-50877HIGH7.5An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying files with names cont...
CVE-2026-50876MEDIUM5.4A cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attackers to execute arbitrary web scripts or HT...
CVE-2026-50875HIGH8.1Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers...
CVE-2026-50874HIGH8.1An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allo...
CVE-2026-50873CRITICAL9.8An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to exec...
CVE-2026-50872CRITICAL9.8An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitra...
CVE-2026-50871CRITICAL9.8An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscenc...
CVE-2026-50870HIGH7.5An information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows attacker...