CVE Vulnerability Database

Search and browse 375,847 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-73219MEDIUM5.3CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user...
CVE-2026-73218HIGH7.7Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in A...
CVE-2026-73217HIGH7.7Cursor is a code editor built for programming with AI. Prior to 3.1.2, Cursor IDE for macOS allows an agent running in A...
CVE-2026-73216MEDIUM6.5Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in sr...
CVE-2026-73215HIGH7.1Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, turnports_allocate_even() in src/a...
CVE-2026-73214HIGH8.2Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and cr...
CVE-2026-73213MEDIUM5.8Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_tu...
CVE-2026-73212MEDIUM5.8Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_...
CVE-2026-73211CRITICAL9.8PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolat...
CVE-2026-73090CRITICAL9.3PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVi...
CVE-2026-72713HIGH8.7XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-cre...
CVE-2026-72712MEDIUM6.5Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash ...
CVE-2026-71398CRITICAL10Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code...
CVE-2026-71362CRITICAL9.1Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An att...
CVE-2026-69113MEDIUM5.4Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authentica...
CVE-2026-69102CRITICAL9.8MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.proper...
CVE-2026-65680MEDIUM6.7Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to el...
CVE-2026-48790MEDIUM5.5Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the us...
CVE-2026-48771HIGH8.2ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed du...
CVE-2026-48767HIGH7.6TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain ...
CVE-2026-48494HIGH7.1TypeBot is a chatbot builder tool. In version 3.16.1, an authenticated user who has read access to any typebot can resum...
CVE-2026-48447HIGH7.7Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution ...
CVE-2026-48441HIGH8.6Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulne...
CVE-2026-48416HIGH7.5Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A...
CVE-2026-48415HIGH7.6Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A...