CVE Vulnerability Database

Search and browse 395,242 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-6739HIGH7.2Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-...
CVE-2026-6689MEDIUM4.3Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Fail to enforce Permiss...
CVE-2026-6046MEDIUM5.3Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a...
CVE-2026-53982HIGH7.1Cap-go Console < 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker...
CVE-2026-53981HIGH7.6Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacke...
CVE-2026-47224MEDIUM4.3NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6....
CVE-2026-47222MEDIUM5.4NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6....
CVE-2026-3840HIGH7.1A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a crafted version strin...
CVE-2026-3433MEDIUM4.3Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to restrict role_u...
CVE-2026-9641MEDIUM5.3Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default alg...
CVE-2026-9638HIGH7.5Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These versions use the built...
CVE-2026-8828HIGH8.8A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users...
CVE-2026-5792MEDIUM6.5Authentication bypass by spoofing vulnerability in Hedef Media Promotion Interactive Media Marketing Inc. Related Market...
CVE-2026-53568MEDIUM6.9Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, there is a stored XSS vulnerab...
CVE-2026-50560MEDIUM5.3Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-50091HIGH7.4Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses h...
CVE-2026-50090MEDIUM6.1The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due ...
CVE-2026-50089MEDIUM6.1The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redire...
CVE-2026-50088MEDIUM4.7The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara...
CVE-2026-50087MEDIUM6.1The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an inst...
CVE-2026-50086CRITICAL9.8The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing ke...
CVE-2026-50085CRITICAL9.8The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's ...
CVE-2026-50084MEDIUM6.5The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to...
CVE-2026-50083CRITICAL9.8The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-...
CVE-2026-50082MEDIUM5.3The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the att...