CVE Vulnerability Database

Search and browse 397,888 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-41069MEDIUM6.5libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file...
CVE-2026-40864MEDIUM4.3JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through ...
CVE-2026-3294HIGH8.8An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjac...
CVE-2026-5843HIGH8.6The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and exe...
CVE-2026-5817HIGH8.6The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loadin...
CVE-2026-40610MEDIUM5.5BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1...
CVE-2026-40607HIGH7.5Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.11.0 through 2.28.1, a Stored XSS vulnerabi...
CVE-2026-40598MEDIUM6.9Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the re...
CVE-2026-40597HIGH7.6Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS ...
CVE-2026-40596HIGH7.2Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.11.0 through 2.28.1 allow any authenticated us...
CVE-2026-40295MEDIUM6.1Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module...
CVE-2026-39824LOW3.3NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum siz...
CVE-2026-9291HIGH7.5Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remot...
CVE-2026-6406HIGH8.8The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When EC...
CVE-2026-48700CRITICAL9.3An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI...
CVE-2026-40172HIGH8.1authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PAT...
CVE-2026-40166HIGH7.1authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authent...
CVE-2026-39970HIGH8.5TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain a critical stored XSS vulnerability in the app.type...
CVE-2026-39969MEDIUM6.5TypeBot is a chatbot builder tool. In versions 3.16.0 and prior, the WhatsApp Cloud API webhook endpoint (POST /v1/works...
CVE-2026-39968HIGH7.1TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via ...
CVE-2026-39967LOW3.1TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the bot engine's the findResult query does not filter r...
CVE-2026-39966MEDIUM6.5TypeBot is a chatbot builder tool. In versions 3.15.2, the getLinkedTypebots API endpoint returns full bot definitions t...
CVE-2026-46727HIGH8.1An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getadd...
CVE-2026-42627MEDIUM6.2In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumElements() in armnn/Tensor.cpp allows a craft...
CVE-2026-39965HIGH7.7TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via Open Redirect Bypass as the HTTP Reques...