CVE Vulnerability Database

Search and browse 379,570 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-70599MEDIUM5.9Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7,...
CVE-2026-70598LOW3.9Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10...
CVE-2026-70597MEDIUM6.3Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,...
CVE-2026-70596MEDIUM4.3Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user ...
CVE-2026-70595MEDIUM4Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, s...
CVE-2026-60053CRITICAL9.1Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Admin...
CVE-2026-60023HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache An...
CVE-2026-53992MEDIUM6.1ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php that allows remot...
CVE-2026-50749MEDIUM6.5Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authentica...
CVE-2026-49331MEDIUM6.5A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy for...
CVE-2026-48912MEDIUM6.5Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ...
CVE-2026-48911HIGH7.5Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: throug...
CVE-2026-48834HIGH7.5Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: t...
CVE-2026-39924MEDIUM6.8Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid sess...
CVE-2026-39923CRITICAL9.2Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers t...
CVE-2026-32835Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-18531MEDIUM5.3IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use ...
CVE-2026-16442CRITICAL9.8A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authenti...
CVE-2026-15656MEDIUM4.3IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cook...
CVE-2026-15587CRITICAL9.4Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows...
CVE-2026-15572HIGH8.8A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mappe...
CVE-2026-13477HIGH8.8IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privilege...
CVE-2026-12762MEDIUM5.3IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensiti...
CVE-2026-12730LOW3.8IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 throug...
CVE-2026-10025CRITICAL9.8IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injec...