CVE Vulnerability Database

Search and browse 378,066 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-48113HIGH8.5Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated client...
CVE-2026-48063CRITICAL9.3Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baile...
CVE-2026-48061MEDIUM5.9Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypa...
CVE-2026-41447HIGH8.5FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbit...
CVE-2026-18738MEDIUM4.7Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote att...
CVE-2026-18737HIGH7.1Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL...
CVE-2026-18736MEDIUM5.3Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the serve...
CVE-2026-18733HIGH8.8A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors...
CVE-2026-18648MEDIUM5.3A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDat...
CVE-2026-18647HIGH7.3A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue ...
CVE-2026-18646MEDIUM5.5A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system...
CVE-2026-18645MEDIUM5.4A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /sys...
CVE-2026-69198MEDIUM6.9ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, ev...
CVE-2026-69192HIGH7.7ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 ac...
CVE-2026-69185HIGH7.5Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a sp...
CVE-2026-68981HIGH7.5Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding...
CVE-2026-68980CRITICAL9.1Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts throu...
CVE-2026-68979CRITICAL9.8Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization...
CVE-2026-67599HIGH8.6ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attacke...
CVE-2026-67598CRITICAL9.1Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that all...
CVE-2026-66296MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-sit...
CVE-2026-62354MEDIUM4.3Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients wit...
CVE-2026-58139MEDIUM6.5The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with S...
CVE-2026-48031CRITICAL9.1go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 202...
CVE-2026-47211HIGH8.4Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to ...