CVE Vulnerability Database

Search and browse 398,037 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-28830MEDIUM4.7A race condition was addressed with additional validation. This issue is fixed in macOS Tahoe 26.4. An app may be able t...
CVE-2026-28819MEDIUM5.4An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 1...
CVE-2026-20696MEDIUM5.5An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS ...
CVE-2026-8321HIGH7.3A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the f...
CVE-2026-8320MEDIUM4.7A security vulnerability has been detected in jishenghua jshERP up to 3.6. This affects the function getUserByWeixinCode...
CVE-2026-8319MEDIUM5.5A weakness has been identified in aiwaves-cn agents up to e8c4e3c2d19739d3dff59e577d1c97090cc15f59. Affected by this iss...
CVE-2026-6146MEDIUM5.3Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys. Amazon::Credentials stores c...
CVE-2026-45026MEDIUM6.8WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vuln...
CVE-2026-45025MEDIUM6.8WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vuln...
CVE-2026-42887MEDIUM4.5Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.33.0, a stored cross-site scripting (XSS) vulne...
CVE-2026-42886MEDIUM4.9Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/backups/upload endpoint dec...
CVE-2026-42885MEDIUM4.3Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/filesystem/pathexists endpo...
CVE-2026-42884MEDIUM4.3Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/collections and GET /api/col...
CVE-2026-42883MEDIUM6.5Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/libraries/:id/download endpo...
CVE-2026-42882CRITICAL9.4oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused ...
CVE-2026-42876MEDIUM4.9External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete...
CVE-2026-42875MEDIUM5.3External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete...
CVE-2026-42874LOW3.7Microdot is a minimalistic Python web framework. Prior to 2.6.1, the Response.set_cookie() method does not sanitize its ...
CVE-2026-42873NONE0WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, when attempting to upload a file with m...
CVE-2026-42872MEDIUM6.1WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a reflected Cross-Site Scripting (XSS) v...
CVE-2026-42870MEDIUM6.4WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a Stored Cross-Site Scripting (XSS) flaw...
CVE-2026-42869CRITICAL10SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57,...
CVE-2026-42565MEDIUM4.3@workos/authkit-session is a toolkit for building WorkOS AuthKit framework integrations. Prior to 0.5.1, an open redirec...
CVE-2026-42050MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-21 and 6.9...
CVE-2026-36734HIGH8.8EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection. An authenticated attacker with access to the network can su...