CVE Vulnerability Database

Search and browse 377,880 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-69250HIGH8.5Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 toke...
CVE-2026-68494HIGH8.7The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint byp...
CVE-2026-67618MEDIUM6.5marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operat...
CVE-2026-67200HIGH8.7Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary...
CVE-2026-67199HIGH7.1Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop...
CVE-2026-67198HIGH8.7Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauth...
CVE-2026-67196MEDIUM5.4Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to in...
CVE-2026-67195HIGH8.8Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitr...
CVE-2026-61515CRITICAL9.8Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allo...
CVE-2026-61514CRITICAL9.8Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthent...
CVE-2026-18770HIGH7.3A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an un...
CVE-2026-18766MEDIUM6.3A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affect...
CVE-2026-18650HIGH8.8Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MY...
CVE-2026-18401MEDIUM6.9The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in S...
CVE-2026-11368MEDIUM6.5The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning chann...
CVE-2026-70368MEDIUM6.5A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log m...
CVE-2026-70367MEDIUM5.4A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS pr...
CVE-2026-17070HIGH8.8Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained b...
CVE-2026-14337MEDIUM4.6Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a use...
CVE-2026-70373HIGH8.8Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by conc...
CVE-2026-70372HIGH8.8Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request pa...
CVE-2026-70371HIGH8.8Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request ...
CVE-2026-70370HIGH8.8Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Colu...
CVE-2026-70369HIGH8.8Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-con...
CVE-2026-63252HIGH7.5In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message ch...