CVE Vulnerability Database

Search and browse 381,601 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-13113MEDIUM5.3GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2...
CVE-2026-12436HIGH8.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 1...
CVE-2026-12357HIGH7.2Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability ...
CVE-2025-14562LOW3.1GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 1...
CVE-2026-67429CRITICAL10Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related fi...
CVE-2026-67428HIGH8.5Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules includi...
CVE-2026-67427HIGH8.6Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable ...
CVE-2026-67426CRITICAL9.3Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verifica...
CVE-2026-67425HIGH8.6Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys ...
CVE-2026-67424HIGH8.5Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP modules http.get, ht...
CVE-2026-67201HIGH8.6V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows...
CVE-2026-66737Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-62995LOW2.3joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar...
CVE-2026-59898HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final,...
CVE-2026-2482HIGH8.8IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which c...
CVE-2026-16328HIGH8.6In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing ...
CVE-2026-16326CRITICAL10In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may all...
CVE-2026-14529CRITICAL9.8IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 t...
CVE-2026-13346MEDIUM6.5pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary lo...
CVE-2026-12935HIGH8.7The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based b...
CVE-2026-10684LOW3In subsys/debug/coredump/coredump_shell.c, print_coredump_hdr() used the 16-bit tgt_code field of a stored Zephyr coredu...
CVE-2026-8497HIGH7.4Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0...
CVE-2026-59920MEDIUM6.5Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Fina...
CVE-2026-59919MEDIUM5.5Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Fina...
CVE-2026-59901HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ...