CVE Vulnerability Database

Search and browse 397,974 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-39428MEDIUM4.8CubeCart is an ecommerce software solution. Prior to 6.6.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in ...
CVE-2026-39358HIGH7.2CubeCart is an ecommerce software solution. Prior to 6.6.0, Authenticated Time-Based Blind SQL Injection vulnerabilities...
CVE-2026-21821HIGH8.3The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1...
CVE-2025-27853HIGH7.3The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU we...
CVE-2025-27852MEDIUM5The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack...
CVE-2025-27851CRITICAL9.3The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attac...
CVE-2025-27850HIGH7.5The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics pac...
CVE-2026-44364CRITICAL9.3MISP modules are autonomous modules that can be used to extend MISP for new services. In 3.0.7 and earlier, a Cross-Site...
CVE-2026-44363MEDIUM5.8MISP modules are autonomous modules that can be used to extend MISP for new services. Prior to 3.0.7, an unsafe remote r...
CVE-2026-44351CRITICAL9.1fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerabili...
CVE-2026-42552HIGH7.5Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the default error handler Engine::_error() writes the ...
CVE-2026-42551HIGH7.5Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Request::getMethod() unconditionally honors the X-HTTP...
CVE-2026-42550HIGH8.8Flight is an extensible micro-framework for PHP. Prior to 3.18.1, SimplePdo::insert(), SimplePdo::update(), and SimplePd...
CVE-2026-42549MEDIUM4.4Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the make:controller CLI command calls mkdir(..., recur...
CVE-2026-42548HIGH8.6Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Flight::jsonp() concatenates the ?jsonp= query paramet...
CVE-2026-33381HIGH8.1When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few ...
CVE-2026-33380MEDIUM6.5A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's fi...
CVE-2026-33378MEDIUM6.5Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the s...
CVE-2026-33377HIGH7.1An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have wr...
CVE-2026-33376HIGH7.4When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask expl...
CVE-2026-28383MEDIUM6.5A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request b...
CVE-2026-28380MEDIUM6.5Any Editor could delete any snapshot, even if they have no access to read or write them.
CVE-2026-28379MEDIUM6.5A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concur...
CVE-2026-28376MEDIUM6.5The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming req...
CVE-2026-28374MEDIUM4.3Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read t...