CVE Vulnerability Database

Search and browse 397,840 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-48555HIGH7.4Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows rem...
CVE-2026-47266HIGH8.7Formie is a Craft CMS plugin for creating forms. Prior to 2.2.21 and 3.1.26, unauthenticated users could modify existing...
CVE-2026-47123HIGH7.5FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.220, the email processin...
CVE-2026-46599HIGH7.5The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit...
CVE-2026-46527HIGH7.5cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, When the server has c...
CVE-2026-46385HIGH7.5iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-contro...
CVE-2026-46384HIGH7.5iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, several Avro decoder paths read attacker-controlled 64-bit val...
CVE-2026-45700CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an...
CVE-2026-45697CRITICAL9.8Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted ...
CVE-2026-45613LOW3.3Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a heap-buffer-overflow in librz/bi...
CVE-2026-45372CRITICAL9.9cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's se...
CVE-2026-45352HIGH7.5cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size i...
CVE-2026-45324LOW3.3Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a double free in librz/core/cmd/cm...
CVE-2026-45294MEDIUM5.3FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset ...
CVE-2026-45151LOW2.9NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In 0.24.8 and earlier, quic_stream_recv can derefe...
CVE-2026-45149HIGH7.5The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0....
CVE-2026-44640MEDIUM4.5NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->prov_data is stored as nni_...
CVE-2026-44422HIGH8.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts on...
CVE-2026-44421HIGH8.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a h...
CVE-2026-44420HIGH8.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a h...
CVE-2026-44287MEDIUM6.3FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at projects/code-sandbox/...
CVE-2026-44285HIGH7.7FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allo...
CVE-2026-42500MEDIUM5.3Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid ...
CVE-2026-34127MEDIUM4.8A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG...
CVE-2026-9051CRITICAL9.3There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an ...