CVE Vulnerability Database

Search and browse 381,217 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-12945HIGH7.1IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs throug...
CVE-2026-12940CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable ...
CVE-2026-12932HIGH8.1A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 all...
CVE-2026-11885HIGH8.4IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A careful...
CVE-2026-11771HIGH7.5OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the...
CVE-2026-67596MEDIUM6.9CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticate...
CVE-2026-58222HIGH8.8A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Do...
CVE-2026-58216MEDIUM5.3An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) servi...
CVE-2026-57862HIGH8.5Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass...
CVE-2026-52680CRITICAL9.8Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary...
CVE-2026-4978CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffi...
CVE-2026-48910MEDIUM6.5A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the mar...
CVE-2026-44617MEDIUM6.5LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constru...
CVE-2026-44616MEDIUM6.5LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escap...
CVE-2026-44613MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin ...
CVE-2026-28814HIGH7.5Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain s...
CVE-2026-28813HIGH8.8Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommende...
CVE-2026-28812CRITICAL9.8UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate pri...
CVE-2026-28811HIGH7.5Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to ver...
CVE-2026-28323CRITICAL9.8SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2...
CVE-2026-23985MEDIUM6.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The...
CVE-2026-23981MEDIUM4.3An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to upd...
CVE-2026-15658HIGH8.1A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint t...
CVE-2026-15657MEDIUM6.5A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor mercha...
CVE-2026-10842HIGH7.5IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 T...