CVE Vulnerability Database

Search and browse 398,130 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-4397MEDIUM6.8Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker c...
CVE-2025-4386MEDIUM6.8Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to ...
CVE-2026-44349HIGH7.1Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.5, processFuzzySearch in server/resource/resource_finda...
CVE-2026-44264MEDIUM4.3Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other...
CVE-2026-44263MEDIUM4.3Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowe...
CVE-2026-42011HIGH7.4A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when p...
CVE-2026-41689MEDIUM6Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the webhook notifica...
CVE-2026-41688HIGH7.7Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF ...
CVE-2026-41687MEDIUM4.3Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.8.1, the SSRF protection in en...
CVE-2026-41654HIGH8.1Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (de...
CVE-2026-41650MEDIUM6.1fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version ...
CVE-2026-41519MEDIUM5.4Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions ...
CVE-2026-41505HIGH8.7RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation ...
CVE-2026-41422HIGH8.3Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.4, the /aggregate/:typename endpoint accepted column an...
CVE-2026-36458CRITICAL9.8ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated i...
CVE-2026-32686MEDIUM6.9Uncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service. The ...
CVE-2025-67202MEDIUM6.1Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vul...
CVE-2025-63706CRITICAL9.8NPM package next-npm-version1.0.1 is vulnerable to Command injection.
CVE-2025-63705HIGH8.8NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.
CVE-2026-6795CRITICAL9.6URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive...
CVE-2026-41685MEDIUM4.3Incus is a system container and virtual machine manager. Prior to version 7.0.0, uploads of large amount of data by auth...
CVE-2026-41684MEDIUM6.5Incus is a system container and virtual machine manager. Prior to version 7.0.0, backup.GetInfo() trusts the inline back...
CVE-2026-41648MEDIUM5Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image and backup tarballs...
CVE-2026-41647MEDIUM6.5Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an ...
CVE-2026-41589CRITICAL9.6Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP...