CVE Vulnerability Database

Search and browse 397,836 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-45278MEDIUM6.1Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2.2, an attacker can ...
CVE-2026-45277LOW3.3Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, authenticated users can check if arb...
CVE-2026-45275MEDIUM6.5Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability...
CVE-2026-43958HIGH7.8A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a ...
CVE-2026-43625HIGH8.2CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attackers to intercept impo...
CVE-2026-43624HIGH8.8F5-TTS through version 1.1.20 contains a path traversal vulnerability in the finetune Gradio handlers that allows unauth...
CVE-2026-43623HIGH8.8microtar through 0.1.0 contains a stack-based buffer overflow vulnerability in the raw_to_header() function in src/micro...
CVE-2026-41013HIGH8.1Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF s...
CVE-2026-40990MEDIUM6.5OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Produc...
CVE-2026-40989MEDIUM6.5Under infinite recursion in the routing layer, request-handling can cause OOM error. Affected Spring Products and Versi...
CVE-2026-37235HIGH7.5FlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without binding it to the sender's SCTP association. T...
CVE-2026-37233HIGH7.5FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism. The equality function eq_xapp_ri...
CVE-2026-37232HIGH8.6An issue was discovered in OpenAirInterface5G 2.4.0 (nr-softmodem) in the E2SM-KPM RAN Function's PRB utilization metric...
CVE-2026-37231HIGH7.5FlexRIC v2.0.0 uses a uint16_t counter for xapp_id assignment but stores the value in uint32_t message fields. After 65,...
CVE-2026-37230HIGH7.5FlexRIC v2.0.0 crashes when the near-RT RIC receives a RIC_INDICATION message with a ran_func_id that does not exist in ...
CVE-2026-37229HIGH7.5FlexRIC v2.0.0 contains a reachable assertion in e2ap_create_pdu() triggered when ASN.1 PER decoding fails. A remote una...
CVE-2026-37228HIGH7.5FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The function allocates a f...
CVE-2026-37226HIGH7.5FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node. The lo...
CVE-2026-30963LOW2.7Capsule is a multi-tenancy and policy-based framework for Kubernetes. To defend against namespace hijacking achieved thr...
CVE-2026-23638MEDIUM6.5Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerabil...
CVE-2026-22872CRITICAL9.1Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin pri...
CVE-2026-10283MEDIUM6.3A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function of the component Setti...
CVE-2026-10282MEDIUM5.3A security vulnerability has been detected in Bottelet DaybydayCRM up to 2.2.1. This impacts the function view of the fi...
CVE-2026-10281HIGH7.3A weakness has been identified in Enderfga claw-orchestrator up to 3.5.5. This affects the function EmbeddedServer of th...
CVE-2026-10280HIGH7.3A security flaw has been discovered in horizon921 mcpilot 0.1.0. The impacted element is an unknown function of the file...