CVE Vulnerability Database

Search and browse 397,814 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-44281HIGH7GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0...
CVE-2026-42321HIGH8.4GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a tech...
CVE-2026-42320MEDIUM5.9GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0...
CVE-2026-42318HIGH7GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11....
CVE-2026-42317HIGH7GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0...
CVE-2026-3276MEDIUM6.3unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs...
CVE-2026-37462HIGH7.5An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a...
CVE-2026-36748CRITICAL9RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.
CVE-2026-36576CRITICAL9.8An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 al...
CVE-2026-36574HIGH7.8A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and e...
CVE-2022-31114MEDIUM5.1backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha...
CVE-2026-8404MEDIUM5.3An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware...
CVE-2026-7666LOW3.1An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` ...
CVE-2026-6873MEDIUM4.3An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in...
CVE-2026-5241CRITICAL9.6A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-control...
CVE-2026-48587MEDIUM5.3An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Djan...
CVE-2026-47325MEDIUM6.9ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's password...
CVE-2026-47324MEDIUM5.1ProjectsAndPrograms school-management-system is vulnerable to Stored Cross‑Site Scripting (XSS) in multiple attributes o...
CVE-2026-44546MEDIUM5.3daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket...
CVE-2026-44545HIGH7.5daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Beca...
CVE-2026-37460HIGH7.5Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 all...
CVE-2026-35193LOW3.1An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware...
CVE-2026-10729LOW1.2An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists i...
CVE-2025-70101MEDIUM6.5An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows att...
CVE-2025-70100MEDIUM5.5A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library...