CVE Vulnerability Database

Search and browse 397,814 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-14772HIGH8.8Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24...
CVE-2025-14771CRITICAL9.9Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0...
CVE-2026-4035HIGH7.7A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gatew...
CVE-2025-15654HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague ...
CVE-2026-5078MEDIUM5.3Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization reque...
CVE-2026-50052LOW2.3In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to l...
CVE-2026-50031HIGH7.5ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Manag...
CVE-2026-10705LOW3.1A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/datafram...
CVE-2026-10704HIGH7.3A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the func...
CVE-2026-10703MEDIUM6.3A security vulnerability has been detected in EIPStackGroup OpENer up to 2.3.0. Affected is the function CreateMessageRo...
CVE-2026-9516HIGH7.5Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter...
CVE-2026-9334HIGH7.3Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref i...
CVE-2026-10694HIGH7.3A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function i...
CVE-2026-10693MEDIUM6.3A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulner...
CVE-2026-9732MEDIUM4.3The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forger...
CVE-2026-7421MEDIUM4.4The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu...
CVE-2026-10692MEDIUM4.3A weakness has been identified in johnhuang316 code-index-mcp up to 2.14.0. Affected is the function is_safe_regex_patte...
CVE-2026-10691MEDIUM4.3A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function o...
CVE-2026-10690MEDIUM6.3A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of ...
CVE-2026-44654HIGH8.1LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a sha...
CVE-2026-44653MEDIUM6.5LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, users...
CVE-2026-42507MEDIUM5.3When returning errors, functions in the net/textproto package would include its input as part of the error. This might a...
CVE-2026-42504HIGH7.5Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.
CVE-2026-41412MEDIUM4.9alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to versio...
CVE-2026-40108HIGH7.1GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XS...