CVE Vulnerability Database

Search and browse 398,067 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-28860HIGH7.5The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 an...
CVE-2026-28848HIGH7.5A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Tahoe ...
CVE-2026-28847HIGH8.8The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9,...
CVE-2026-28846HIGH7.5A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS ...
CVE-2026-28840HIGH7.8A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonom...
CVE-2026-28830MEDIUM4.7A race condition was addressed with additional validation. This issue is fixed in macOS Tahoe 26.4. An app may be able t...
CVE-2026-28819MEDIUM5.4An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 1...
CVE-2026-20696MEDIUM5.5An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS ...
CVE-2026-8321HIGH7.3A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the f...
CVE-2026-8320MEDIUM4.7A security vulnerability has been detected in jishenghua jshERP up to 3.6. This affects the function getUserByWeixinCode...
CVE-2026-8319MEDIUM5.5A weakness has been identified in aiwaves-cn agents up to e8c4e3c2d19739d3dff59e577d1c97090cc15f59. Affected by this iss...
CVE-2026-6146MEDIUM5.3Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys. Amazon::Credentials stores c...
CVE-2026-45026MEDIUM6.8WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vuln...
CVE-2026-45025MEDIUM6.8WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vuln...
CVE-2026-42887MEDIUM4.5Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.33.0, a stored cross-site scripting (XSS) vulne...
CVE-2026-42886MEDIUM4.9Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/backups/upload endpoint dec...
CVE-2026-42885MEDIUM4.3Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/filesystem/pathexists endpo...
CVE-2026-42884MEDIUM4.3Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/collections and GET /api/col...
CVE-2026-42883MEDIUM6.5Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/libraries/:id/download endpo...
CVE-2026-42882CRITICAL9.4oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused ...
CVE-2026-42876MEDIUM4.9External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete...
CVE-2026-42875MEDIUM5.3External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete...
CVE-2026-42874LOW3.7Microdot is a minimalistic Python web framework. Prior to 2.6.1, the Response.set_cookie() method does not sanitize its ...
CVE-2026-42873NONE0WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, when attempting to upload a file with m...
CVE-2026-42872MEDIUM6.1WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a reflected Cross-Site Scripting (XSS) v...