CVE Vulnerability Database

Search and browse 381,202 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-62323MEDIUM6.3Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the se...
CVE-2026-55502HIGH7.1Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin r...
CVE-2026-55499MEDIUM4.3Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscri...
CVE-2026-55497MEDIUM6.5Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image ...
CVE-2026-55496MEDIUM4.3Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActi...
CVE-2026-55495MEDIUM4.3Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-W...
CVE-2026-43833MEDIUM5.3Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-43832HIGH7.5Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-43831HIGH7.5Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-43830CRITICAL9.8Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-43829HIGH7.5Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-6890Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-6889Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-18157HIGH7.8A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit ...
CVE-2026-14541HIGH7.5An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mc...
CVE-2026-14540MEDIUM6.1A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-t...
CVE-2026-14539HIGH7.5An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up ...
CVE-2026-14538HIGH7.7An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Googl...
CVE-2026-14537CRITICAL9.8Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0...
CVE-2026-58039LOW3.3A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-wr...
CVE-2026-66720HIGH7.1The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherTy...
CVE-2026-66421CRITICAL9.3OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to ...
CVE-2026-66420HIGH8.8MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated...
CVE-2026-66369HIGH7.1The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-...
CVE-2026-66364HIGH7.1The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 mu...