CVE Vulnerability Database

Search and browse 397,845 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-45668CRITICAL9.3Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas...
CVE-2026-45661CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerab...
CVE-2026-45660MEDIUM5.4Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image prox...
CVE-2026-45633CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injecti...
CVE-2026-45632CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enfor...
CVE-2026-45631CRITICAL10Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SEC...
CVE-2026-45630CRITICAL9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection...
CVE-2026-45629CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection...
CVE-2026-45628CRITICAL9.6Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands ...
CVE-2026-45627HIGH8.2Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticat...
CVE-2026-45626MEDIUM6.3Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /enviro...
CVE-2026-45625CRITICAL9.9Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-bas...
CVE-2026-45577MEDIUM6.9Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public...
CVE-2026-44697HIGH8.6Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-...
CVE-2026-43917MEDIUM5.3Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.19.0 and earlier, the protectedProcedure middleware ...
CVE-2026-10108HIGH8.7xiaomusic v0.5.7 contains an unauthenticated path traversal vulnerability in the GET /music/{file_path:path} endpoint th...
CVE-2026-10107HIGH7.7MoviePilot v2 contains a server-side request forgery vulnerability in the image proxy endpoint that allows authenticated...
CVE-2026-10105HIGH8.7agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inj...
CVE-2026-10070MEDIUM5.1A vulnerability was found in macrozheng mall up to 1.0.3. This affects an unknown function of the file /admin/update/ of...
CVE-2026-9194——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-48501CRITICAL9.1GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization h...
CVE-2026-45663CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability ...
CVE-2026-45662HIGH8.8Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dok...
CVE-2026-44962CRITICAL9.9Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied...
CVE-2026-39276HIGH7.2The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrator...