CVE Vulnerability Database

Search and browse 397,974 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-42881HIGH8.4STIGQter is an open-source reimplementation of DISA's STIG Viewer. From 0.1.2 to before 1.2.7, an attacker can achieve l...
CVE-2026-42559HIGH8.8RMCP is an official Rust SDK for the Model Context Protocol. Prior to version 1.4.0, the rmcp crate's Streamable HTTP se...
CVE-2026-42457CRITICAL9vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prio...
CVE-2026-42186HIGH7.5OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace del...
CVE-2026-41937HIGH8.6Vvveb before 1.0.8.3 contains an unrestricted file upload vulnerability in the plugin upload endpoint that allows super_...
CVE-2026-41935HIGH7.1Vvveb before 1.0.8.3 contains an uncontrolled recursion vulnerability in the admin controller dispatch cycle where Base:...
CVE-2026-41933MEDIUM6.9Vvveb before 1.0.8.3 contains a directory listing information disclosure vulnerability that allows unauthenticated attac...
CVE-2026-41932MEDIUM6.1Vvveb before 1.0.8.3 contains a stored cross-site scripting vulnerability in the customer signup flow where the Signup::...
CVE-2026-24712HIGH7.3Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.
CVE-2026-24711MEDIUM5.3Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.
CVE-2026-24710MEDIUM6.1Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS.
CVE-2026-21730MEDIUM6.1Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unaut...
CVE-2025-69443MEDIUM6.3Remote Code Execution in coleam00 Archon 0.1.0. A crafted HTML page, when accessed by a victim, can execute commands, ru...
CVE-2025-62628HIGH7Unsafe OpenSSL initialization within some AMD optional tools may allow a local user-privileged attacker to inject a mali...
CVE-2025-62625MEDIUM6Improper privilege management in the KVM key download component could allow an attacker to swap tokens and download sens...
CVE-2025-62619MEDIUM6.3Missing authentication in the KVM key download endpoint could allow an unauthenticated attacker with knowledge of the ex...
CVE-2026-6638HIGH8.8SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table cre...
CVE-2026-6637HIGH8.8Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as th...
CVE-2026-6575MEDIUM4.3Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which cau...
CVE-2026-6479HIGH7.5Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX ...
CVE-2026-6478MEDIUM6.5Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover us...
CVE-2026-6477HIGH8.8Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lsee...
CVE-2026-6476HIGH7.2SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitra...
CVE-2026-6475HIGH8.8Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite loca...
CVE-2026-6474MEDIUM4.3Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server...