CVE Vulnerability Database

Search and browse 397,870 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-33221MEDIUM6NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an i...
CVE-2026-9565MEDIUM6.3A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dangerous of the file a...
CVE-2026-9564LOW2.4A vulnerability was found in SourceCodester/oretnom23 Hospitals Patient Records Management System 1.0. The impacted elem...
CVE-2026-9562HIGH7.3A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Th...
CVE-2026-8852HIGH7.5IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module.
CVE-2026-8850HIGH7.5IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload.
CVE-2026-48905MEDIUM6.1Lack of input filtering leads to an XSS vector in the HTML filter code.
CVE-2026-48904CRITICAL9.8An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
CVE-2026-48903MEDIUM6.1Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
CVE-2026-48902CRITICAL9.8The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't e...
CVE-2026-48901HIGH7.5The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
CVE-2026-48900MEDIUM4.3An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
CVE-2026-48899CRITICAL9.8An improper access check allows privilege escalation through the com_users batch task.
CVE-2026-48898CRITICAL9.8An improper access check allows privilege escalation through the com_users batch task.
CVE-2026-48897HIGH7.5Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-48896HIGH7.5Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-48864HIGH7.8A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed...
CVE-2026-48697HIGH7.4FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_w...
CVE-2026-48693MEDIUM5.5FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via predictable file paths in /tmp. T...
CVE-2026-48691CRITICAL9.8FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp...
CVE-2026-48690HIGH7.1FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer alloc...
CVE-2026-48126HIGH8.2Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --let...
CVE-2026-48091——Rejected reason: Further research determined the issue is not a vulnerability.
CVE-2026-47728MEDIUM4.3Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink resolved sourcemaps and debug files by debug ID wi...
CVE-2026-47716LOW3.1Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, In affected versions, the issue list view authorizes acces...