CVE Vulnerability Database

Search and browse 395,159 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-42890MEDIUM4.8Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron ...
CVE-2026-42851HIGH7.8Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty term...
CVE-2026-42850HIGH8.8Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the ...
CVE-2026-42604MEDIUM6.9Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server version...
CVE-2026-53726MEDIUM6.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-53725MEDIUM5.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8...
CVE-2026-53724LOW2.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-53408HIGH8.1Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7....
CVE-2026-53407CRITICAL9.8Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7....
CVE-2026-50244MEDIUM6.9The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbit...
CVE-2026-50108HIGH8.7The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifyin...
CVE-2026-50101CRITICAL9.2Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued to the device on each...
CVE-2026-50099MEDIUM5.1During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated WPA keys in clearte...
CVE-2026-50008MEDIUM6.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8...
CVE-2026-47248MEDIUM6.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-47236MEDIUM4.3Solidtime is an open-source time-tracking app. Prior to version 0.12.2, Solidtime defines an explicit invitations:view a...
CVE-2026-47138HIGH8.7Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-42947HIGH8.8A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently...
CVE-2026-42932MEDIUM6.9Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predict...
CVE-2026-42306HIGH7.2Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and ...
CVE-2026-41568MEDIUM6.1Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and ...
CVE-2026-28742CRITICAL9.8Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmwar...
CVE-2026-12143HIGH7.5form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argumen...
CVE-2026-12043HIGH8.8Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote ...
CVE-2026-10715MEDIUM5.1Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft autosave endpoint. A low-...