CVE Vulnerability Database

Search and browse 398,130 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-42284CRITICAL9.8GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_...
CVE-2026-42215HIGH8.8GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitP...
CVE-2026-42214HIGH7.8Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to version 0.14, NotepadNext's detectLanguageFrom...
CVE-2026-41906HIGH7.1FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.214, the Change ...
CVE-2026-41905HIGH7.7FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::san...
CVE-2026-41904HIGH7.6FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with...
CVE-2026-41903MEDIUM5.4FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user hold...
CVE-2026-41902CRITICAL9.1FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-s...
CVE-2026-41653HIGH7BentoPDF is a client-side PDF toolkit that is self hostable. Prior to version 2.8.3, a cross-site scripting vulnerabilit...
CVE-2026-8081MEDIUM6.3A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality...
CVE-2026-37709CRITICAL9.8Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958...
CVE-2026-7415CRITICAL9.8The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read ...
CVE-2026-7414CRITICAL9.8Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials ar...
CVE-2026-7413CRITICAL9.8A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authen...
CVE-2026-7821CRITICAL9.1Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthen...
CVE-2026-6973HIGH7.2An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authentic...
CVE-2026-5788CRITICAL9.8An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticat...
CVE-2026-5787CRITICAL9.1An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unaut...
CVE-2026-5786HIGH8.8An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote...
CVE-2026-36388MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/...
CVE-2026-36387MEDIUM6.5A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This...
CVE-2026-36341MEDIUM5.4Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supp...
CVE-2025-65122HIGH7.5Regex Denial of Service in youtube-regex npm package through version 1.0.5.
CVE-2025-63704CRITICAL9.8NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user ...
CVE-2025-63703CRITICAL9.8npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js().