CVE Vulnerability Database

Search and browse 375,585 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-66382MEDIUM4.3An authenticated user may write files outside the intended Artifactory work directory under specific conditions.
CVE-2026-66381MEDIUM5.3A repository reader with cache-deploy permission may access content outside a configured upstream path under specific co...
CVE-2026-66380MEDIUM4.3An authenticated user without repository read permission may access private OCI referrer metadata under specific conditi...
CVE-2026-66379MEDIUM4.3An authenticated user may view private Puppet module metadata without repository read access.
CVE-2026-66378MEDIUM4.3An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
CVE-2026-66377MEDIUM5.3An unauthenticated user may access restricted repository information under specific conditions.
CVE-2026-66376MEDIUM4.2Credentials for a deleted user may remain valid for a short period under specific conditions.
CVE-2026-66375HIGH8.1A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific...
CVE-2026-50561CRITICAL9.4Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version ...
CVE-2026-49349MEDIUM6.8regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvert...
CVE-2026-49262LOW3In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is ...
CVE-2026-47234MEDIUM4.4Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::se...
CVE-2026-47233MEDIUM6.5Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `...
CVE-2026-18171MEDIUM5.7Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the und...
CVE-2026-14479MEDIUM5.5A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation ...
CVE-2026-14478HIGH7.8A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to in...
CVE-2025-59324CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is ...
CVE-2025-59323CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partition...
CVE-2025-59322CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted v...
CVE-2025-59321CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the syst...
CVE-2025-59320CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk s...
CVE-2025-59319CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and...
CVE-2026-67285CRITICAL9.2Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An u...
CVE-2026-47232MEDIUM4.3Admidio is an open-source user management solution. Prior to version 5.0.10, the sensitive `mode=export` action in `modu...
CVE-2026-47231HIGH8.1Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-c...