CVE Vulnerability Database

Search and browse 395,305 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-44495HIGH7.7Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contain...
CVE-2026-44494HIGH8.7Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vuln...
CVE-2026-44492HIGH8.6Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise I...
CVE-2026-44490HIGH8.2Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-sid...
CVE-2026-44489MEDIUM5.3Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created b...
CVE-2026-44488HIGH7.5Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce co...
CVE-2026-44487HIGH7.5Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapt...
CVE-2026-44486HIGH7.5Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapte...
CVE-2026-11945HIGH7.5PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON docume...
CVE-2026-9648CRITICAL9.1The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certi...
CVE-2026-7870HIGH8.8IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malici...
CVE-2026-7787HIGH8.1IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypass...
CVE-2026-53777HIGH8.6Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary co...
CVE-2026-4096MEDIUM6.1IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by th...
CVE-2026-3341MEDIUM5.4IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allo...
CVE-2026-11839CRITICAL9.9Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows ...
CVE-2024-45636MEDIUM4.4IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileg...
CVE-2026-8406HIGH7.1openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticate...
CVE-2026-6338MEDIUM4.9A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13...
CVE-2026-53723MEDIUM5.8Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to descri...
CVE-2026-53661HIGH8.8Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized iden...
CVE-2026-38581CRITICAL9.8SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitra...
CVE-2026-11816HIGH8.1Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `...
CVE-2026-10847HIGH7.8A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated lo...
CVE-2026-7852CRITICAL9.8Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclu...