CVE Vulnerability Database

Search and browse 397,974 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-40328——Rejected reason: This CVE is a duplicate of another CVE.
CVE-2026-40327——Rejected reason: This CVE is a duplicate of another CVE.
CVE-2026-32993HIGH8.3Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated a...
CVE-2026-32992HIGH8.2SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the...
CVE-2026-29205HIGH8.6Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdav...
CVE-2026-8328MEDIUM5.9The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to rep...
CVE-2026-45714CRITICAL9.1CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulne...
CVE-2026-45708HIGH7.2CubeCart is an ecommerce software solution. Prior to 6.7.3, an admin with documents edit permission can save raw <?php …...
CVE-2026-45229HIGH8.8Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated...
CVE-2026-45228MEDIUM5.4Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the...
CVE-2026-45055HIGH8.1CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the...
CVE-2026-45054MEDIUM4.9CubeCart is an ecommerce software solution. Prior to 6.7.0, the admin orders-transactions listing page (admin.php?_g=ord...
CVE-2026-45053CRITICAL9.1CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists ...
CVE-2026-44418HIGH8.7EcclesiaCRM is CRM Software for church management. In 8.0.0 and earlier, the ValidateInput() function's default case in ...
CVE-2026-44381MEDIUM5.3MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed ...
CVE-2026-44380HIGH7.2MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerabili...
CVE-2026-44379MEDIUM5.3MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4...
CVE-2026-44377CRITICAL9.1CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulne...
CVE-2026-44376MEDIUM6.1CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthenticated Reflected XSS vulnerability exists in the...
CVE-2026-44373MEDIUM5.3Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by send...
CVE-2026-44372MEDIUM6.1Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could turn a redirect route rule using ...
CVE-2026-44368MEDIUM6.9PyQuorum is a cryptographic library for secret sharing and key management. Prior to 0.2.1, the mul_mod function implemen...
CVE-2026-42602HIGH8.1azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in...
CVE-2026-42561HIGH7.5Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service v...
CVE-2026-42304HIGH7.5Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.n...