CVE Vulnerability Database

Search and browse 375,825 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-64934MEDIUM5.3The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, witho...
CVE-2026-5917CRITICAL9.6libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command inj...
CVE-2026-29036HIGH7.5cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointe...
CVE-2026-19560HIGH8.8Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-19559HIGH8.8Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code insi...
CVE-2026-19558HIGH7.5Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to instal...
CVE-2026-19557HIGH8.3Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised...
CVE-2026-19556HIGH8.8Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside...
CVE-2026-18710HIGH8.2A MongoDB driver component could write sensitive configuration information, including a credential used for outbound net...
CVE-2026-71290CRITICAL9.1Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolic...
CVE-2026-66832MEDIUM6.9When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is app...
CVE-2026-66154HIGH8.3An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1...
CVE-2026-66150HIGH7.8Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows...
CVE-2026-66149HIGH7.8Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows...
CVE-2026-66148MEDIUM6.3An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.10...
CVE-2026-66147CRITICAL9.4An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier...
CVE-2026-63177HIGH7.1Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Ng...
CVE-2026-63134MEDIUM5.4Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction w...
CVE-2026-63133MEDIUM6.5Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives...
CVE-2026-55676HIGH8.8Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `P...
CVE-2026-48765CRITICAL9.9TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspa...
CVE-2026-48763HIGH8.2TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/t...
CVE-2026-48762MEDIUM5.4TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a u...
CVE-2026-29035HIGH8.3CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that...
CVE-2026-19579MEDIUM5.4Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request ...