CVE Vulnerability Database

Search and browse 398,082 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-42183MEDIUM6.5Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From ve...
CVE-2026-42174MEDIUM4.3Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement ...
CVE-2026-42137MEDIUM6.5Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.acc...
CVE-2026-42069MEDIUM6.5Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, read access to site, user and role...
CVE-2026-42051MEDIUM4.3Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, the system API endpoint leaks lice...
CVE-2026-41311MEDIUM6.5LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.7, a circular...
CVE-2026-41163HIGH7bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is i...
CVE-2026-8207HIGH7Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/gr...
CVE-2026-7652MEDIUM5.3The LatePoint plugin for WordPress is vulnerable to Account Takeover via Weak Password Recovery Mechanism in the unauthe...
CVE-2026-6667MEDIUM4.3PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users ...
CVE-2026-6666HIGH7.5A possible null pointer reference in PgBouncer before 1.25.2 could lead to a crash, if a server sends an error response ...
CVE-2026-6665CRITICAL9.8The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the conten...
CVE-2026-6664HIGH7.5An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to ...
CVE-2026-41705HIGH8.6Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized...
CVE-2026-44313CRITICAL9.1Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. Prior...
CVE-2026-42455HIGH8.8Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In ve...
CVE-2026-45130MEDIUM5.5Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compou...
CVE-2026-44987LOW3.8SysReptor is a fully customizable pentest reporting platform. Prior to version 2026.29, users with "User Admin" permissi...
CVE-2026-44656MEDIUM5.3Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists...
CVE-2026-44286LOW2.3FastGPT is an AI Agent building platform. Prior to version 4.14.17, an unauthenticated Server-Side Request Forgery (SSRF...
CVE-2026-44284MEDIUM6.3FastGPT is an AI Agent building platform. Prior to version 4.14.17, FastGPT had an inconsistent SSRF protection gap in M...
CVE-2026-42556CRITICAL9Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who c...
CVE-2026-42456MEDIUM4.3AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-42454CRITICAL9.9Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v...
CVE-2026-42453HIGH8.7Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v...