CVE Vulnerability Database

Search and browse 397,933 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-33052MEDIUM5.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.0 and 2.28.1 allow a low-privileged authent...
CVE-2026-32323HIGH7.8Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may...
CVE-2026-32312MEDIUM4.3GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with f...
CVE-2026-32244MEDIUM5.3Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1...
CVE-2026-30950HIGH7.1AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-27964LOW3.9FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-...
CVE-2026-27892MEDIUM6.5FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores...
CVE-2026-27891HIGH7.2FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerabi...
CVE-2026-27737MEDIUM6.5BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation for...
CVE-2026-8851HIGH8.6SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionalit...
CVE-2026-8838CRITICAL9.8Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver befor...
CVE-2026-4137HIGH7.8In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py` cr...
CVE-2026-27130CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection throu...
CVE-2026-26978HIGH8.6FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize dat...
CVE-2026-25244CRITICAL9.8WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appiu...
CVE-2026-22810HIGH7.3Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior...
CVE-2026-47092HIGH7.8Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attac...
CVE-2026-47091MEDIUM4.8Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to r...
CVE-2026-47090MEDIUM4.6Claude HUD through 0.0.12, patched in commit 234d9aa, constructs OSC 8 terminal hyperlink escape sequences using raw cwd...
CVE-2026-45246MEDIUM6.8Summarize prior to 0.15.1 contains an insecure file permission vulnerability in the refresh-free configuration rewrite p...
CVE-2026-45245HIGH7.4Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch ...
CVE-2026-45244MEDIUM5.4Summarize prior to 0.15.1 contains a missing authorization vulnerability that allows attackers to execute browser automa...
CVE-2026-21789MEDIUM4.6HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certai...
CVE-2025-65954MEDIUM6.1SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions bel...
CVE-2026-8836CRITICAL9.8A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/sn...