CVE Vulnerability Database

Search and browse 395,134 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-45013HIGH8.1ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 have a password r...
CVE-2026-45012HIGH7.6ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 contain an authen...
CVE-2026-45011HIGH7.3ApostropheCMS is an open-source Node.js content management system. Version 4.29.0 has a stored cross-site scripting vuln...
CVE-2026-44990CRITICAL9.3ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer wi...
CVE-2026-44786HIGH7.5Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be...
CVE-2026-44785MEDIUM4.3Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be...
CVE-2026-44784MEDIUM6.5Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be...
CVE-2026-44783MEDIUM5.4Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be...
CVE-2026-44782MEDIUM4.3Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be...
CVE-2026-44780MEDIUM4.3Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be...
CVE-2026-44779MEDIUM4.3Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be...
CVE-2026-42853MEDIUM6.5ApostropheCMS is an open-source Node.js content management system. Versions of the @apostrophecms/cli package up to and ...
CVE-2026-24618MEDIUM4.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HashThemes Hash Elements all...
CVE-2026-12130LOW3.5A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of t...
CVE-2026-12129LOW3.5A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this issue is some unknown...
CVE-2026-54361HIGH8.8MISP contained multiple mass assignment vulnerabilities in the handling of collections, tag collections, event delegatio...
CVE-2026-54360HIGH8.4A mass assignment vulnerability exists in MISP’s sharing group creation endpoint. When creating a new sharing group, the...
CVE-2026-54359HIGH7.1MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. W...
CVE-2026-54358HIGH7.5An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accou...
CVE-2026-54357MEDIUM5.1An improper authorization vulnerability in MISP allowed an authenticated organization administrator to access or modify ...
CVE-2026-54055MEDIUM5Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability ex...
CVE-2026-50552MEDIUM6.3Koel is a free, open-source music streaming solution. Prior to version 9.7.1, Koel contains a Server-Side Request Forger...
CVE-2026-50287HIGH8.7AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a ...
CVE-2026-47260HIGH7.7Koel is a free, open-source music streaming solution. Prior to version 9.3.5, Koel validates the podcast feed URL via th...
CVE-2026-43872MEDIUM5.3Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints are affected by a path...