CVE Vulnerability Database

Search and browse 375,825 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-71468MEDIUM5.3A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly ...
CVE-2026-71467HIGH7.5A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authent...
CVE-2026-70339MEDIUM5.4Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2026-66146MEDIUM6.1Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions ...
CVE-2026-66145CRITICAL9.1An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier version...
CVE-2026-65655LOW2.3When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to ...
CVE-2026-48813HIGH8.7Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have a...
CVE-2026-48804HIGH7.5python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server store...
CVE-2026-45618CRITICAL10LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbit...
CVE-2026-19091HIGH8.1The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ...
CVE-2026-18844HIGH8.1The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (...
CVE-2026-16230CRITICAL9.8The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path vali...
CVE-2026-13457HIGH7.5The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all ...
CVE-2024-14042MEDIUM6.3A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/hss_ogs_diam_s6a_ulr...
CVE-2026-73228MEDIUM5.3Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing ...
CVE-2026-73227HIGH8.1electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al...
CVE-2026-73226HIGH8.8electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm al...
CVE-2026-73225HIGH8.1electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al...
CVE-2026-73224HIGH8.8electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al...
CVE-2026-73223HIGH8.1electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al...
CVE-2026-73222HIGH8.8Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio ...
CVE-2026-73221MEDIUM5.3CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user...
CVE-2026-72742CRITICAL9.2DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attacke...
CVE-2026-69119HIGH8.3Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any aut...
CVE-2026-69117MEDIUM6.5NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only...