CVE Vulnerability Database

Search and browse 375,825 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-19550MEDIUM4.3A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rath...
CVE-2026-18634HIGH8.4An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (B...
CVE-2026-15606HIGH8.8The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i...
CVE-2026-14863HIGH8.8FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated at...
CVE-2026-73283LOW2.5In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwar...
CVE-2026-73282MEDIUM4.8In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operat...
CVE-2026-73281LOW3.5In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, includi...
CVE-2026-73244MEDIUM5.3kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /li...
CVE-2026-73243MEDIUM5.8kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /add...
CVE-2026-73242HIGH8.3FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos...
CVE-2026-73241HIGH8.3FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreer...
CVE-2026-73235MEDIUM6.1FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constru...
CVE-2026-73234HIGH7.8FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() i...
CVE-2026-73233HIGH8.5FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the FEM Displacement Constraint t...
CVE-2026-73232HIGH7.5ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory...
CVE-2026-73231HIGH7.8Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method ...
CVE-2026-73230MEDIUM5.9Ente provides end-to-end encrypted cloud services and security tools. Prior to 2026.07.28, Ente 2of3 card format version...
CVE-2026-73229MEDIUM4.3Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's...
CVE-2026-73036MEDIUM4.6Bash-it 3.2.0 contains a terminal escape sequence injection vulnerability in the barbuk theme's Python virtualenv prompt...
CVE-2026-73034CRITICAL9.8DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary f...
CVE-2026-73032CRITICAL9.6PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary Jav...
CVE-2026-73031HIGH8.7telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary J...
CVE-2026-71845MEDIUM6.3A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes...
CVE-2026-71475MEDIUM5A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data ...
CVE-2026-71474MEDIUM6.3A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, whic...