CVE Vulnerability Database

Search and browse 398,143 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-41674HIGH7.5xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom...
CVE-2026-41673HIGH7.5xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom...
CVE-2026-41672HIGH7.5xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom...
CVE-2026-41671MEDIUM6.8Admidio is an open-source user management solution. Prior to version 5.0.9, the OIDC token introspection endpoint (/modu...
CVE-2026-41670HIGH8.2Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO...
CVE-2026-41669HIGH8.2Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio SAML Identity Provider implement...
CVE-2026-41663LOW3.5Admidio is an open-source user management solution. Prior to version 5.0.9, several administrative operations in Admidio...
CVE-2026-41662MEDIUM5.2Admidio is an open-source user management solution. Prior to version 5.0.9, Role::stopMembership() does not verify wheth...
CVE-2026-41661MEDIUM6.1Admidio is an open-source user management solution. Prior to version 5.0.9, an unauthenticated attacker can execute arbi...
CVE-2026-41660HIGH7.1Admidio is an open-source user management solution. Prior to version 5.0.9, a logic error in Admidio's two-factor authen...
CVE-2026-41659LOW2.7Admidio is an open-source user management solution. Prior to version 5.0.9, the member assignment DataTables endpoint (m...
CVE-2026-41658MEDIUM6.5Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio inventory module enforces author...
CVE-2026-41657MEDIUM4.9Admidio is an open-source user management solution. Prior to version 5.0.9, the contacts_data.php endpoint uses a weaker...
CVE-2026-41656MEDIUM4.5Admidio is an open-source user management solution. Prior to version 5.0.9, the add mode in modules/documents-files.php ...
CVE-2026-41655MEDIUM6.5Admidio is an open-source user management solution. Prior to version 5.0.9, the ecard_preview.php endpoint does not vali...
CVE-2026-41640HIGH8.8NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t...
CVE-2026-41587HIGH8.6CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-41203CRITICAL9.4CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-41202CRITICAL9.4CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-41201CRITICAL9.1CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-41142HIGH8.8OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-41004MEDIUM4.4When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Sp...
CVE-2026-41002HIGH8.1The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git reposi...
CVE-2026-40982CRITICAL9.1Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server ...
CVE-2026-40981HIGH7.5When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the co...