CVE Vulnerability Database

Search and browse 398,067 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-43894MEDIUM5.5jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX...
CVE-2026-43640HIGH8.6Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an or...
CVE-2026-43639CRITICAL9.1Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user t...
CVE-2026-43638MEDIUM5.4Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to...
CVE-2026-42865MEDIUM4.3Inbox Zero is an AI personal assistant for email. Prior to 2.29.3, the cleaner email stream endpoint used a shared Redis...
CVE-2026-42860HIGH8.5The Open edx Enterprise Service app provides enterprise features to the Open edX platform. From 7.0.2 to 7.0.4, the sync...
CVE-2026-42859HIGH8.1Neat VNC is a VNC server library. Prior to 0.9.6, a pre-authentication stack buffer overflow exists in neatvnc in the RS...
CVE-2026-42858CRITICAL9.9Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in...
CVE-2026-42857MEDIUM5.4Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_ht...
CVE-2026-42856HIGH8.7Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to 5.1.3, the MCP HTTP transport accepts JSON-RPC too...
CVE-2026-42316MEDIUM6.5kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (Kusto). Prior to 5.2...
CVE-2026-42315MEDIUM6.5pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name...
CVE-2026-42314MEDIUM6.5pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are s...
CVE-2026-42313HIGH8.3pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API...
CVE-2026-42312MEDIUM6.8pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API...
CVE-2026-41431HIGH8Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mo...
CVE-2026-41257MEDIUM5.5jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in...
CVE-2026-41256MEDIUM5.5jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncate...
CVE-2026-41250MEDIUM5.7Taiga is a project management platform for startups and agile developers. Prior 6.9.1, Taiga front is vulnerable to stor...
CVE-2026-40612MEDIUM5.5jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth...
CVE-2026-3609HIGH7.8Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vuln...
CVE-2026-3048LOW3.8An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3...
CVE-2026-38569MEDIUM5.4HireFlow v1.2 is vulnerable to Cross Site Scripting (XSS) in candidate_detail.html via the Resume or Feedback Comment fi...
CVE-2026-38568HIGH8.1HireFlow v1.2 is vulnerable to Incorrect Access Control. The application does not enforce object-level authorization on ...
CVE-2026-38567CRITICAL9.8HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints. User-supplied input is concatenated di...