CVE Vulnerability Database

Search and browse 397,873 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-9503LOW3.3A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file sr...
CVE-2026-9502MEDIUM5.3A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the fil...
CVE-2026-9501LOW3.3A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section...
CVE-2026-9500MEDIUM5.3A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section ...
CVE-2026-48852LOW3.7PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.
CVE-2026-48851LOW3.1PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not c...
CVE-2026-48850MEDIUM5.9PuTTY 0.72 before 0.84 has a double free in RSA KEX.
CVE-2026-48589MEDIUM5.4Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In ...
CVE-2026-44598MEDIUM5.4With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vu...
CVE-2026-43828MEDIUM6.5Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue...
CVE-2026-43827MEDIUM6.5Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 ...
CVE-2026-24597MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart allows Cross Site Request Forgery. This ...
CVE-2026-24574MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Fo...
CVE-2026-24545MEDIUM4.3Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Contro...
CVE-2026-9498MEDIUM6.3A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass ...
CVE-2026-9497MEDIUM6.3A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject ...
CVE-2026-9486MEDIUM4.3A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part...
CVE-2026-9485LOW3.5A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some un...
CVE-2026-9484MEDIUM6.3A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is...
CVE-2026-48849MEDIUM4.4In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored valu...
CVE-2026-48848HIGH7.2Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascadi...
CVE-2026-48847LOW3.7Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redi...
CVE-2026-48846MEDIUM6.5In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a...
CVE-2026-48845MEDIUM6.5In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for U...
CVE-2026-48844HIGH7.5Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues o...