CVE Vulnerability Database

Search and browse 397,851 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-48525MEDIUM5.3PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the u...
CVE-2026-48524LOW3.7PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP r...
CVE-2026-48523MEDIUM5.4PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list ...
CVE-2026-48522MEDIUM4.2PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to url...
CVE-2026-48156LOW3.3pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can cr...
CVE-2026-48155MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can cr...
CVE-2026-47762MEDIUM5.4TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via f...
CVE-2026-47761MEDIUM5.4TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in th...
CVE-2026-47760MEDIUM5.4TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by ...
CVE-2026-47759MEDIUM5.4TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via u...
CVE-2026-45017HIGH7.5Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.0, the built-in FileSystemLoader and Cac...
CVE-2026-44672CRITICAL9.3mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30...
CVE-2026-44594HIGH7.5esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI...
CVE-2026-44593HIGH8.7esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, the legacy router first ret...
CVE-2026-44358HIGH8.2Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior t...
CVE-2026-41565HIGH7.5CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers. The gcm_dec...
CVE-2026-35676HIGH8.8phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint ...
CVE-2026-35675HIGH8.8phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthe...
CVE-2026-35672HIGH8.7phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in API v4.0 where the default empty api.apiClientT...
CVE-2026-35671HIGH8.8phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint...
CVE-2026-9828LOW2.9Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-...
CVE-2026-8990MEDIUM5.3A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant...
CVE-2026-8980CRITICAL9.3The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-priv...
CVE-2026-8979CRITICAL9.3The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated re...
CVE-2026-49238HIGH8.4An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server)...