CVE Vulnerability Database

Search and browse 377,753 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-67858HIGH7.5Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast di...
CVE-2026-67857HIGH7.5open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/u...
CVE-2026-67856HIGH7.5An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscri...
CVE-2026-67855HIGH7.5open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMA...
CVE-2026-52370MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execu...
CVE-2026-51144MEDIUM6.1Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker ...
CVE-2026-45103HIGH7.5OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP...
CVE-2026-45100CRITICAL9.1OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta ...
CVE-2026-45084HIGH8.7OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5 contain a denial of ...
CVE-2026-18817LOW2.2A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAut...
CVE-2026-18816MEDIUM5A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file...
CVE-2026-18814HIGH7.3A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. Th...
CVE-2026-70588MEDIUM5Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin fail...
CVE-2026-70554CRITICAL9.8MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary cod...
CVE-2026-70494HIGH8.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELE...
CVE-2026-70493MEDIUM6.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built...
CVE-2026-70492HIGH8.7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/...
CVE-2026-70491MEDIUM6.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /ap...
CVE-2026-70490MEDIUM6.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the termi...
CVE-2026-70489MEDIUM6.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automatio...
CVE-2026-70488MEDIUM4.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync ...
CVE-2026-70487MEDIUM5.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline di...
CVE-2026-67979CRITICAL9.1Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows at...
CVE-2026-66902CRITICAL9.8Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated sy...
CVE-2026-66901HIGH7.5Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated...