CVE Vulnerability Database

Search and browse 398,130 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-8131HIGH7.3A security flaw has been discovered in SourceCodester SUP Online Shopping 1.0. This impacts an unknown function of the f...
CVE-2026-8130HIGH7.3A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. This affects an unknown function of the file /...
CVE-2026-8129HIGH7.3A vulnerability was determined in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of...
CVE-2026-44298MEDIUM4.9Kimai is an open-source time tracking application. From version 2.32.0 to before version 2.56.0, users with the role Sys...
CVE-2026-43944CRITICAL9.6electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before ...
CVE-2026-43943HIGH7.8electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.9, a code...
CVE-2026-43942MEDIUM5.5electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, ...
CVE-2026-43941CRITICAL9.6electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, ...
CVE-2026-43940HIGH8.4electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.16, the r...
CVE-2026-42275HIGH8.7zrok is software for sharing web services, files, and network resources. Prior to version 2.0.2, the zrok WebDAV drive b...
CVE-2026-42274HIGH7.8Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall ...
CVE-2026-42273HIGH7.8Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall ...
CVE-2026-42272HIGH7.8Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall ...
CVE-2026-42271HIGH8.8LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before vers...
CVE-2026-42267MEDIUM5.7Kimai is an open-source time tracking application. From version 2.27.0 to before version 2.54.0, any ROLE_USER can creat...
CVE-2026-42264CRITICAL9.1Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive con...
CVE-2026-42261HIGH7.1PromptHub is an all-in-one AI toolbox for prompt, skill, and agent management. From version 0.4.9 to before version 0.5....
CVE-2026-42208CRITICAL9.8LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before ver...
CVE-2026-42203HIGH8.8LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before vers...
CVE-2026-42150MEDIUM4.8wlc is a Weblate command-line client using Weblate's REST API. Prior to version 2.0.0, the HTML output format in wlc emb...
CVE-2026-41900CRITICAL10OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code exec...
CVE-2026-41646MEDIUM5.5Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulner...
CVE-2026-41645MEDIUM5.3Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulner...
CVE-2026-41501CRITICAL9.8electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a comm...
CVE-2026-41500CRITICAL9.8electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a comm...