CVE Vulnerability Database

Search and browse 397,817 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-41577HIGH7.5authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response proces...
CVE-2026-40181MEDIUM6.1React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to th...
CVE-2026-38967CRITICAL9.8CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.
CVE-2026-35202LOW2.3Pterodactyl is a free, open-source game server management panel. Prior to version 1.12.3, the Pterodactyl Client API has...
CVE-2026-35049MEDIUM6.5wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon receiving a crafted m...
CVE-2026-34993HIGH7.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJ...
CVE-2026-34077HIGH7.5React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Co...
CVE-2026-33553MEDIUM6.1Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS.
CVE-2026-33245MEDIUM4.7React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Co...
CVE-2026-30586MEDIUM6.1Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sensitive information v...
CVE-2026-28299HIGH7.5SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause...
CVE-2026-1829HIGH8.8The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up t...
CVE-2026-10702MEDIUM4.3JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.
CVE-2026-10701HIGH7.5Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 151.0.3.
CVE-2026-10617HIGH7.3A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects the function resolveAut...
CVE-2026-10616MEDIUM4.3A weakness has been identified in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function TeamTasksTo...
CVE-2026-10608HIGH7.3A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the file /plus/carbuyactio...
CVE-2026-10607HIGH7.3A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspecialchars of the file...
CVE-2026-10584HIGH8.2Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow rem...
CVE-2025-64390HIGH7.4A privilege escalation vulnerability exists in PlayStation 4 firmware versions 13.00 through 13.02. The BD-J (Blu-ray Di...
CVE-2021-4479MEDIUM6.3Dräger Atlan A350 versions 1.00 up to and including 1.01 contains an improper input handling vulnerability that allows a...
CVE-2021-4478HIGH8.3Dräger CC-Vision Basic before 7.5.3 and Dräger CC-Vision E-Cal before 7.2.5.0 contain an out-of-bounds write vulnerabili...
CVE-2019-25724HIGH7.1Dräger Infinity M300 patient worn monitors with software version VG2.x and earlier contain a network-based denial of ser...
CVE-2019-25723MEDIUM6.3Dräger Perseus A500 software versions 2.00 through 2.02 contains an improper input handling vulnerability that allows ex...
CVE-2019-25722HIGH7.6Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard-coded plaintext credentia...