CVE Vulnerability Database

Search and browse 397,888 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-39964MEDIUM5.4TypeBot is a chatbot builder tool. In versions prior to 3.16.0, the Typebot viewer (packages/embeds/js) renders anchor t...
CVE-2026-9255HIGH8.4Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to ex...
CVE-2026-42626MEDIUM5.9HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetD...
CVE-2026-37470HIGH7.3An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login p...
CVE-2026-36228HIGH7.3Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execu...
CVE-2026-36227MEDIUM6.5Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and e...
CVE-2026-36226MEDIUM6.1Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensit...
CVE-2026-34207HIGH7.6TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection for Webhook / HTTP Request blocks valida...
CVE-2026-33712CRITICAL10Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typeb...
CVE-2026-32253CRITICAL9.8Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate a...
CVE-2026-28735MEDIUM5.4Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the OAuth...
CVE-2026-28445HIGH8.7Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButton component in the embed package renders...
CVE-2026-28444MEDIUM6.5Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the getResultLogs API endpoint authorizes the caller ag...
CVE-2026-9251MEDIUM5.4Missing authorization in the entry status management feature in Devolutions Server allows a non-administrator authentica...
CVE-2026-9249LOW3.1Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the pr...
CVE-2026-9248LOW2.6Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write acce...
CVE-2026-9247LOW2.4Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissi...
CVE-2026-9246MEDIUM4.3Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated...
CVE-2026-9245MEDIUM5Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated r...
CVE-2026-9224MEDIUM4.3Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory ...
CVE-2026-9223MEDIUM4.3Missing authorization in the vault import feature in Devolutions Server  2026.1.16.0 and earlier allows a low-privileged...
CVE-2026-9047HIGH7.6Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows...
CVE-2026-8477LOW2.7Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server al...
CVE-2026-7325HIGH7.1Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authentica...
CVE-2026-5171MEDIUM4.3Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access...