CVE Vulnerability Database

Search and browse 377,618 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-67422HIGH7.5pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, ...
CVE-2026-65400CRITICAL9.8An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS...
CVE-2026-64677MEDIUM5.9Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not ...
CVE-2026-64665HIGH8.1Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was ...
CVE-2026-64664MEDIUM4.3Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont...
CVE-2026-64663MEDIUM6.5Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-sup...
CVE-2026-64662MEDIUM6.5Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont...
CVE-2026-64655LOW2.1GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify  builds the certificate S...
CVE-2026-64654MEDIUM5.3GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed ex...
CVE-2026-64653MEDIUM5.1GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable pat...
CVE-2026-64652LOW3.3GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characte...
CVE-2026-63725HIGH8.6sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a ta...
CVE-2026-63637HIGH8.6Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter....
CVE-2026-62857HIGH8.8Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the...
CVE-2026-61632MEDIUM5.3PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.2...
CVE-2026-5857CRITICAL9.2Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking ...
CVE-2026-5856HIGH7.1Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no pack...
CVE-2026-5855HIGH8.7Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer lengt...
CVE-2026-5336MEDIUM6.8The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template ren...
CVE-2026-54717MEDIUM5.4Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable...
CVE-2026-53984CRITICAL9.1Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerabilit...
CVE-2026-53983CRITICAL9.2Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital...
CVE-2026-50159MEDIUM5.3Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 ...
CVE-2026-49391MEDIUM5.1Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, Data Import does not escape imported co...
CVE-2026-48088CRITICAL9.4OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...