CVE Vulnerability Database

Search and browse 398,007 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-44166HIGH7.6Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker ...
CVE-2026-43929HIGH8.2ssrfcheck is a library that checks if a string contains a potential SSRF attack. In 1.3.0 and earlier, ssrfcheck fails t...
CVE-2026-43892HIGH8.8AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-cli...
CVE-2026-43891HIGH7.5changedetection.io is a free open source web page change detection tool. Prior to 0.55.1, the vulnerability is caused by...
CVE-2026-42899HIGH7.5Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service o...
CVE-2026-42898CRITICAL9.9Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized a...
CVE-2026-42896HIGH7.8Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-42893HIGH7.5Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz...
CVE-2026-42891MEDIUM6.5User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2026-42838MEDIUM5.4Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Ch...
CVE-2026-42833CRITICAL9.1Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized a...
CVE-2026-42832MEDIUM5.5Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
CVE-2026-42831HIGH7.8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-42830MEDIUM6.5Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
CVE-2026-42825HIGH7Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-42823CRITICAL9.9Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
CVE-2026-42541MEDIUM4.3Kubewarden is a policy engine for Kubernetes. Prior to , An attacker with privileged AdmissionPolicy or AdmissionPolicyG...
CVE-2026-42348HIGH7.5OpenTelemetry.OpAmp.Client is the OpAMP client for OpenTelemetry .NET. Prior to 0.2.0-alpha.1, when receiving responses ...
CVE-2026-42303MEDIUM6.1Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both s...
CVE-2026-42300CRITICAL9.3DevGuard provides vulnerability management for the full software supply chain. Prior to 1.2.2, the SessionMiddleware acc...
CVE-2026-42177MEDIUM5.3linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-...
CVE-2026-42175MEDIUM6.5requests-hardened is a library that overrides the default behaviors of the requests library, and adds new security featu...
CVE-2026-42141HIGH7.7Xibo is an open source digital signage platform with a web content management system and Windows display player software...
CVE-2026-42048CRITICAL9.6Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to...
CVE-2026-42045MEDIUM6.2LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to ...