CVE Vulnerability Database

Search and browse 397,925 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-6095MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Orejime all...
CVE-2026-34744MEDIUM5.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior permit a user to list and downl...
CVE-2026-34600MEDIUM5.7Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2...
CVE-2026-34579MEDIUM5.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior are vulnerable to Authorization...
CVE-2026-5090MEDIUM6.1Template::Plugin::HTML versions before 3.103 for Perl allows HTML and JavaScript to be injected. The html_filter functi...
CVE-2026-34463HIGH8.6Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior contain a Stored XSS vulnerabil...
CVE-2026-34390MEDIUM5.1Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior have a Privilege Escalation vul...
CVE-2026-34358HIGH8.1CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access contr...
CVE-2026-34246MEDIUM4.8CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Sc...
CVE-2026-34241HIGH8.7CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Sc...
CVE-2026-34234CRITICAL10CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (p...
CVE-2025-15645MEDIUM5.1Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due t...
CVE-2024-36343MEDIUM4.6Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to...
CVE-2023-7345MEDIUM6.9Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerability th...
CVE-2026-39250HIGH7.3An authorization vulnerability exists in Innoshop 0.6.0. After logging into the frontend, an attacker can directly acces...
CVE-2026-34233MEDIUM6.5CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, multiple admin controllers...
CVE-2026-34216MEDIUM6.6CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the admin settings update ...
CVE-2026-32882HIGH7.1libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in...
CVE-2026-32814MEDIUM6.5libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid imag...
CVE-2026-32741HIGH7.1libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in ...
CVE-2025-57798MEDIUM5.5Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.6.1...
CVE-2026-42526MEDIUM5.3In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0...
CVE-2026-32740HIGH8.8libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (wr...
CVE-2026-32739MEDIUM6.5libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequen...
CVE-2026-27173HIGH8.7JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kube...