CVE Vulnerability Database

Search and browse 395,250 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-44976MEDIUM5.3Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboard...
CVE-2026-44975MEDIUM5.3Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can res...
CVE-2026-44967MEDIUM5.3OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/m...
CVE-2026-44208MEDIUM6.9Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "su...
CVE-2026-44207MEDIUM6.9Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows a...
CVE-2026-44206MEDIUM6.9Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, DB Schema Enumeration is possi...
CVE-2026-40677HIGH7.7The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle atta...
CVE-2026-8694MEDIUM5.3Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attack...
CVE-2026-7368HIGH8.6The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether ...
CVE-2026-6853CRITICAL9.8Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry ...
CVE-2026-6211HIGH8.7Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Access...
CVE-2026-54133CRITICAL9.8jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON doc...
CVE-2026-53787CRITICAL9.8Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerabili...
CVE-2026-53722MEDIUM5.4Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, <NuxtLink> did not vali...
CVE-2026-53721HIGH8.2Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4...
CVE-2026-47739MEDIUM6.9Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, stored XSS in Note was possibl...
CVE-2026-47244MEDIUM5.3Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-47210CRITICAL9.8vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbi...
CVE-2026-47209HIGH8.6vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in bridge.js (line 1231)...
CVE-2026-47208CRITICAL10vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability...
CVE-2026-47141MEDIUM6.9vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM exposes some process-wide observability bu...
CVE-2026-47140CRITICAL10vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins ...
CVE-2026-47139HIGH8.6vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins...
CVE-2026-47137CRITICAL10vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) ...
CVE-2026-47135HIGH8.7vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-sandbox.js only inte...