CVE Vulnerability Database

Search and browse 398,020 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-31216CRITICAL9.1The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file m...
CVE-2026-31215CRITICAL9.1The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch ...
CVE-2026-31214CRITICAL9.8The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (...
CVE-2026-30810HIGH8.8Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pand...
CVE-2026-30808HIGH8.1Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777...
CVE-2026-30807HIGH8.8Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This i...
CVE-2026-30805CRITICAL9.1Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affect...
CVE-2023-30059MEDIUM5.4An insecure direct object reference in MK-Auth 23.01K4.9 allows attackers to access and send support calls for other use...
CVE-2023-27753HIGH8An arbitrary file upload vulnerability in MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a c...
CVE-2026-8401CRITICAL9.8Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Fir...
CVE-2026-8368MEDIUM6.5LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirect...
CVE-2026-8111HIGH8.8SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attack...
CVE-2026-8110HIGH7.8Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenti...
CVE-2026-8109MEDIUM6.5An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authen...
CVE-2026-8051HIGH7.2OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with...
CVE-2026-8043CRITICAL9.6External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read...
CVE-2026-7432HIGH7A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges...
CVE-2026-7431MEDIUM4.4An incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local a...
CVE-2026-6866HIGH7.5CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclo...
CVE-2026-5061MEDIUM4.7The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper tha...
CVE-2026-43983HIGH8.1Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, Th...
CVE-2026-43939HIGH7.3YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature acc...
CVE-2026-43938HIGH8.1YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNE...
CVE-2026-43937HIGH8.8YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects...
CVE-2026-42260HIGH8.2Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to ...