CVE Vulnerability Database
Search and browse 395,207 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45011 | HIGH | 7.3 | 0.2% | Jun 12, 2026 | ApostropheCMS is an open-source Node.js content management system. Version 4.29.0 has a stored cross-site scripting vuln... |
| CVE-2026-44990 | CRITICAL | 9.3 | 0.6% | Jun 12, 2026 | ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer wi... |
| CVE-2026-44786 | HIGH | 7.5 | 0.3% | Jun 12, 2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be... |
| CVE-2026-44785 | MEDIUM | 4.3 | 0.2% | Jun 12, 2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be... |
| CVE-2026-44784 | MEDIUM | 6.5 | 0.2% | Jun 12, 2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be... |
| CVE-2026-44783 | MEDIUM | 5.4 | 0.1% | Jun 12, 2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be... |
| CVE-2026-44782 | MEDIUM | 4.3 | 0.2% | Jun 12, 2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be... |
| CVE-2026-44780 | MEDIUM | 4.3 | 0.2% | Jun 12, 2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be... |
| CVE-2026-44779 | MEDIUM | 4.3 | 0.2% | Jun 12, 2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be... |
| CVE-2026-42853 | MEDIUM | 6.5 | 0.4% | Jun 12, 2026 | ApostropheCMS is an open-source Node.js content management system. Versions of the @apostrophecms/cli package up to and ... |
| CVE-2026-24618 | MEDIUM | 4.3 | 0.2% | Jun 12, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HashThemes Hash Elements all... |
| CVE-2026-12130 | LOW | 3.5 | 0.2% | Jun 12, 2026 | A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of t... |
| CVE-2026-12129 | LOW | 3.5 | 0.2% | Jun 12, 2026 | A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this issue is some unknown... |
| CVE-2026-54361 | HIGH | 8.8 | 0.3% | Jun 12, 2026 | MISP contained multiple mass assignment vulnerabilities in the handling of collections, tag collections, event delegatio... |
| CVE-2026-54360 | HIGH | 8.4 | 0.2% | Jun 12, 2026 | A mass assignment vulnerability exists in MISP’s sharing group creation endpoint. When creating a new sharing group, the... |
| CVE-2026-54359 | HIGH | 7.1 | 0.2% | Jun 12, 2026 | MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. W... |
| CVE-2026-54358 | HIGH | 7.5 | 0.2% | Jun 12, 2026 | An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accou... |
| CVE-2026-54357 | MEDIUM | 5.1 | 0.3% | Jun 12, 2026 | An improper authorization vulnerability in MISP allowed an authenticated organization administrator to access or modify ... |
| CVE-2026-54055 | MEDIUM | 5 | 0.1% | Jun 12, 2026 | Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability ex... |
| CVE-2026-50552 | MEDIUM | 6.3 | 0.2% | Jun 12, 2026 | Koel is a free, open-source music streaming solution. Prior to version 9.7.1, Koel contains a Server-Side Request Forger... |
| CVE-2026-50287 | HIGH | 8.7 | 0.4% | Jun 12, 2026 | AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a ... |
| CVE-2026-47260 | HIGH | 7.7 | 0.3% | Jun 12, 2026 | Koel is a free, open-source music streaming solution. Prior to version 9.3.5, Koel validates the podcast feed URL via th... |
| CVE-2026-43872 | MEDIUM | 5.3 | 0.3% | Jun 12, 2026 | Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints are affected by a path... |
| CVE-2026-42890 | MEDIUM | 4.8 | 0.1% | Jun 12, 2026 | Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron ... |
| CVE-2026-42851 | HIGH | 7.8 | 0.2% | Jun 12, 2026 | Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty term... |
