CVE Vulnerability Database

Search and browse 398,130 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-7541HIGH7.5A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to...
CVE-2026-6736MEDIUM6.5An authentication bypass vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attack...
CVE-2026-42826HIGH7.5Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose i...
CVE-2026-41929MEDIUM6.1Vvveb before 1.0.8.2 contains an unauthenticated reflected cross-site scripting vulnerability in the visual editor previ...
CVE-2026-41928MEDIUM6.9Vvveb before 1.0.8.2 contains an information disclosure vulnerability in the cron controller that allows unauthenticated...
CVE-2026-41105HIGH8.1Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges ove...
CVE-2026-40214MEDIUM6.3In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. Th...
CVE-2026-40213HIGH7.4OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This un...
CVE-2026-35435CRITICAL10Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges ...
CVE-2026-35428CRITICAL9.6Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unaut...
CVE-2026-34327HIGH8.2Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attac...
CVE-2026-33844CRITICAL9Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code ove...
CVE-2026-33823MEDIUM6.5Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
CVE-2026-33111HIGH7.5Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) all...
CVE-2026-33109CRITICAL9.9Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code ove...
CVE-2026-32207MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an...
CVE-2026-26164HIGH7.5Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz...
CVE-2026-26129HIGH7.5Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz...
CVE-2026-8098HIGH7.3A security vulnerability has been detected in code-projects Feedback System 1.0. Impacted is an unknown function of the ...
CVE-2026-8097MEDIUM6.3A security flaw has been discovered in CodeAstro Online Classroom 1.0. This vulnerability affects unknown code of the fi...
CVE-2026-44365——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-34429. Reason: This candidate is a ...
CVE-2026-42449HIGH8.5n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. In ve...
CVE-2026-42047HIGH8.6Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orche...
CVE-2026-41692MEDIUM4.7i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes....
CVE-2026-41691CRITICAL9.1Copilot said: i18nextify is a JavaScript library that adds i18nextify is a JavaScript library that adds website internat...