CVE Vulnerability Database

Search and browse 380,713 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-70619HIGH8.8Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users ...
CVE-2026-70594MEDIUM6.7Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions ...
CVE-2026-70593MEDIUM6.6Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff...
CVE-2026-70592MEDIUM5.5Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overw...
CVE-2026-70591MEDIUM4.1Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin ima...
CVE-2026-70590MEDIUM4.8Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed password...
CVE-2026-70589MEDIUM4.8Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to rede...
CVE-2026-67862HIGH7.5open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c...
CVE-2026-67861HIGH7.5An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemo...
CVE-2026-67860HIGH7.5open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database ...
CVE-2026-67859HIGH7.5Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discover...
CVE-2026-67858HIGH7.5Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast di...
CVE-2026-67857HIGH7.5open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/u...
CVE-2026-67856HIGH7.5An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscri...
CVE-2026-67855HIGH7.5open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMA...
CVE-2026-52370MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execu...
CVE-2026-51144MEDIUM6.1Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker ...
CVE-2026-45103HIGH7.5OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP...
CVE-2026-45100CRITICAL9.1OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta ...
CVE-2026-45084HIGH8.7OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5 contain a denial of ...
CVE-2026-18817LOW2.2A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAut...
CVE-2026-18816MEDIUM5A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file...
CVE-2026-18814HIGH7.3A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. Th...
CVE-2026-70588MEDIUM5Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin fail...
CVE-2026-70554CRITICAL9.8MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary cod...