CVE Vulnerability Database

Search and browse 398,067 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-42870MEDIUM6.4WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a Stored Cross-Site Scripting (XSS) flaw...
CVE-2026-42869CRITICAL10SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57,...
CVE-2026-42565MEDIUM4.3@workos/authkit-session is a toolkit for building WorkOS AuthKit framework integrations. Prior to 0.5.1, an open redirec...
CVE-2026-42050MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-21 and 6.9...
CVE-2026-36734HIGH8.8EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection. An authenticated attacker with access to the network can su...
CVE-2026-2614HIGH7.5A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 ...
CVE-2022-4988HIGH7.3Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries. Alien::FreeImage contains versi...
CVE-2026-8318MEDIUM5.5A security flaw has been discovered in VectifyAI PageIndex up to f50e52975313c6716c02b20a119577a1929decba. Affected by t...
CVE-2026-7790HIGH7.5Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation. T...
CVE-2026-45224HIGH7.1Crabbox before 0.9.0 contains a path traversal vulnerability in the Islo provider's workspace path resolution that allow...
CVE-2026-45223HIGH8.8Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path whe...
CVE-2026-45222MEDIUM6.9Summarize versions through 0.14.1, fixed in commit 0cfb0fb, creates the daemon configuration directory and file with def...
CVE-2026-43969LOW3.2Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request split...
CVE-2026-43968MEDIUM4Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows SSE event splittin...
CVE-2026-42871MEDIUM6.9WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, atendido/familiar_docfamiliar.php displa...
CVE-2026-42866MEDIUM6.7Tookie is a advanced OSINT information gathering tool. Prior to 4.1fix, modules/modules.py's write_txt, write_csv, write...
CVE-2026-42864CRITICAL9.9FireFighter is an incident management application. Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint ...
CVE-2026-8305CRITICAL9.8A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookR...
CVE-2026-7308MEDIUM5.4An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript t...
CVE-2026-7210HIGH7.5`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow...
CVE-2026-5266LOW2.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo. This vulnerabil...
CVE-2026-5172HIGH7.3A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and ...
CVE-2026-4893MEDIUM5.3An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS pac...
CVE-2026-4892HIGH8.4A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute...
CVE-2026-4891MEDIUM5.3A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a den...