CVE Vulnerability Database

Search and browse 398,007 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-42545MEDIUM5.9Granian is a Rust HTTP server for Python applications. From 0.2.0 to 2.7.4, Granian aborts a worker process if a WSGI ap...
CVE-2026-42544HIGH7.5Granian is a Rust HTTP server for Python applications. From 1.2.0 to 2.7.4, Granian aborts a worker process when an unau...
CVE-2026-42268HIGH7.5ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0....
CVE-2026-42196CRITICAL9.9django-s3file is a lightweight file upload input for Django and Amazon S3. Prior to 7.0.2, S3FileMiddleware is vulnerabl...
CVE-2026-41195MEDIUM5mosparo is the modern solution to protect your online forms from spam. Prior to 1.4.13, the automatic rule package sourc...
CVE-2026-40902HIGH7.5PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, ...
CVE-2026-40863HIGH7.5PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, ...
CVE-2026-35555HIGH7PowerSYSTEM Center feature for device project groups allows an authenticated user with limited permissions to perform an...
CVE-2026-33570MEDIUM6.9PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normall...
CVE-2026-26289HIGH8.4PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to ...
CVE-2026-44403HIGH8.6Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization ...
CVE-2026-44246HIGH7.2nnU-Net is a semantic segmentation framework that automatically adapts its pipeline to a dataset. Prior to 2.4.1, the nn...
CVE-2026-44240HIGH7.5basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when pa...
CVE-2026-44232HIGH8.7DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.3, eve...
CVE-2026-44224HIGH8.8Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbi...
CVE-2026-44012HIGH7.1Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, AssetsController::actionShowInFolder() ...
CVE-2026-44011HIGH8.6Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, Craft CMS which contains an inp...
CVE-2026-44010HIGH7.1Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, the GraphQL Address element res...
CVE-2026-35504MEDIUM5.5PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communicati...
CVE-2025-65088HIGH7.8An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions...
CVE-2025-65087HIGH7.8An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions...
CVE-2025-65086HIGH7.8An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share version...
CVE-2026-8052MEDIUM6HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as ...
CVE-2026-7474HIGH8.8HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path t...
CVE-2026-6959MEDIUM6HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host a...