CVE Vulnerability Database

Search and browse 397,870 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-47715LOW3.1Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink issue event pages accept a direct event identifier...
CVE-2026-46431MEDIUM4.3Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server's Access-Control-Allow-Orig...
CVE-2026-46430MEDIUM4.3Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server bound to 0.0.0.0:5553 on Li...
CVE-2026-45836MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_...
CVE-2026-45835MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_...
CVE-2026-45834MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_...
CVE-2026-45728HIGH7.5Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path...
CVE-2026-45721CRITICAL9Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that res...
CVE-2026-44729HIGH8.7Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fil...
CVE-2026-44723CRITICAL9.9Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pul...
CVE-2026-44680HIGH7.6MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to @mikro-o...
CVE-2026-44502MEDIUM4.3Bugsink is a self-hosted error tracking tool. Prior to 2.1.3, Bugsink’s webhook URL validation could be (partially) bypa...
CVE-2026-44314MEDIUM4.3Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device ...
CVE-2026-43982HIGH8.7Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploadedFileSaveIn() in lua/upload/upload.go use...
CVE-2026-43981HIGH8.2Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engine/luahandler.go, the sync.RWMutex protec...
CVE-2026-40384HIGH7.5An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerabili...
CVE-2026-40383CRITICAL9.8An improper validation of user-supplied input leads to a local file inclusion vulnerability.
CVE-2026-35223CRITICAL9.8An improper access check allows unauthorized access to com_config webservice endpoints.
CVE-2026-35222CRITICAL9.8Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
CVE-2026-35221CRITICAL9.8Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
CVE-2026-35220MEDIUM4.3Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.
CVE-2026-30895MEDIUM6.1Lack of output escaping leads to a XSS vector in the readmore links for com_content.
CVE-2026-30894MEDIUM6.1Lack of output escaping leads to a XSS vector in the content history component.
CVE-2026-2264CRITICAL9.2A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side ...
CVE-2026-25901MEDIUM6.1Lack of output escaping leads to a XSS vector in the multilingual associations component.