CVE Vulnerability Database

Search and browse 378,068 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-48031CRITICAL9.1go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 202...
CVE-2026-47211HIGH8.4Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to ...
CVE-2026-18655HIGH7.1Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs....
CVE-2026-18654MEDIUM6.9Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v...
CVE-2026-18644MEDIUM5.4A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /...
CVE-2026-18641HIGH7.3A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by...
CVE-2026-18632MEDIUM6.3A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of ...
CVE-2026-18631MEDIUM6.3A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig ...
CVE-2026-59913HIGH7.8Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Criti...
CVE-2026-59912HIGH7.8Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnera...
CVE-2026-38447CRITICAL9.8osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with ...
CVE-2026-38446MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread e...
CVE-2026-38444MEDIUM6.1osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is...
CVE-2026-18616CRITICAL9.8A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of...
CVE-2026-18615CRITICAL9.8A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate...
CVE-2026-18614CRITICAL9.8A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file ...
CVE-2025-15631MEDIUM5.9A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing al...
CVE-2025-15630MEDIUM5.9A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with t...
CVE-2025-15629HIGH7.5A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communicati...
CVE-2025-15628HIGH7.5Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between contr...
CVE-2025-15627HIGH7.5A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to...
CVE-2025-15544MEDIUM5.9A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials assoc...
CVE-2026-61524HIGH8.6WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature th...
CVE-2026-61523HIGH8.6WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated...
CVE-2026-40717HIGH7.8Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnera...