CVE Vulnerability Database

Search and browse 398,082 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-42205HIGH8.8Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulne...
CVE-2026-42202MEDIUM6.5nova-toggle-5 enables fliping booleans in the index. Prior to version 1.3.0, the toggle endpoint (POST/nova-vendor/nova-...
CVE-2026-42199MEDIUM6.2Grid is a data structure grid for rust. From version 0.17.0 to before version 1.0.1, an integer overflow in Grid::expand...
CVE-2026-42195LOW3.4draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.9, the draw.io client accepts...
CVE-2026-42193CRITICAL9.1Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accep...
CVE-2026-42192MEDIUM5.4Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, a stored cross-site scripting (X...
CVE-2026-41517NONE0Emlog is an open source website building system. Prior to version 2.6.11, insecure plugin upload functionality allows at...
CVE-2026-41486HIGH8.8Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension typ...
CVE-2026-44400CRITICAL9.8MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile ...
CVE-2026-7807HIGH8.8SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary...
CVE-2026-44694CRITICAL9.1n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. From ...
CVE-2026-42282MEDIUM4.3n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior...
CVE-2026-42190MEDIUM5.3RedwoodSDK is a server-first React framework. From version 1.0.0-beta.50 to before version 1.2.3, server actions in rwsd...
CVE-2026-42189HIGH7.5Russh is a Rust SSH client & server library. Prior to version 0.60.1, a pre-authentication denial-of-service vulnerabili...
CVE-2026-42185MEDIUM5.5People is an application to handle users and teams, and distribute permissions across La Suite. Prior to version 1.25.0,...
CVE-2026-42181MEDIUM6.5Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy fetches metadata for user-suppli...
CVE-2026-42180MEDIUM6.3Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy allows an authenticated low-priv...
CVE-2026-42176MEDIUM6.7Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.67.0, Scoold allows the admins configurat...
CVE-2026-42160CRITICAL10Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. F...
CVE-2026-41495MEDIUM5.3n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior...
CVE-2026-8178CRITICAL9.2An issue exists in Amazon Redshift JDBC Driver versions prior to 2.2.2. Under certain conditions, the driver could load ...
CVE-2026-41511MEDIUM5.5OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Sto...
CVE-2026-29203HIGH8.8A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on ...
CVE-2026-29202HIGH8.8Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution...
CVE-2026-29201HIGH8.6Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary f...