CVE Vulnerability Database

Search and browse 397,933 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-41947CRITICAL9.3Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set ...
CVE-2026-39079HIGH7.5An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitive info...
CVE-2026-26462HIGH7.3Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration...
CVE-2026-42009HIGH7.5A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) pac...
CVE-2026-8803MEDIUM6.3A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file...
CVE-2026-7304CRITICAL9.8SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-lo...
CVE-2026-7302CRITICAL9.1SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an atta...
CVE-2026-7301CRITICAL9.8SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that cal...
CVE-2026-0983HIGH7.1Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 all...
CVE-2026-8802MEDIUM5.3A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function get...
CVE-2026-4320CRITICAL9.3Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to pr...
CVE-2026-41119MEDIUM6.8Dell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A rem...
CVE-2026-7498HIGH8.8Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Informatio...
CVE-2026-6902HIGH7.7A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has ...
CVE-2026-6347HIGH7.6Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fie...
CVE-2026-6346HIGH8.7Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fie...
CVE-2026-6345MEDIUM6.5Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure of created user pass...
CVE-2026-6343MEDIUM4.3Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check public/private permissions whi...
CVE-2026-6339MEDIUM4.3Mattermost versions 11.5.x <= 11.5.1, 11.4.x <= 11.4.3 fail to validate the X-Requested-With header on the burn-on-read ...
CVE-2026-6333MEDIUM5Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response UR...
CVE-2026-5163MEDIUM6.5Mattermost versions 11.5.x <= 11.5.1 fail to verify channel membership when processing AI-assisted message rewrites whic...
CVE-2026-4643LOW3.5Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying ...
CVE-2026-4286MEDIUM4.3Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to check if {{team_id}} was being changed when updating p...
CVE-2026-3471MEDIUM6.5Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in t...
CVE-2026-3117MEDIUM6.5Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions when processing comma...