CVE Vulnerability Database

Search and browse 383,851 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-48390HIGH8.2Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker co...
CVE-2026-48374HIGH7.8Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability th...
CVE-2026-48058MEDIUM4.6nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, intern...
CVE-2026-47768MEDIUM5.5nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-...
CVE-2026-47726HIGH7.1nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, intern...
CVE-2026-47725MEDIUM6.9nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every ...
CVE-2026-18107HIGH7.8A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process insid...
CVE-2026-16771HIGH8.8In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on ...
CVE-2026-16498CRITICAL10The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-H...
CVE-2026-16496HIGH8.9The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful t...
CVE-2026-15992HIGH8.8The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3....
CVE-2026-15304MEDIUM6.5The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions ...
CVE-2026-14869HIGH8.6The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTT...
CVE-2026-59933HIGH7.5PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 t...
CVE-2026-59931HIGH7.7PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 t...
CVE-2026-54635HIGH7.5pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2....
CVE-2026-48388HIGH8.6Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in ...
CVE-2026-48372HIGH7.8Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution i...
CVE-2026-48025MEDIUM6.9nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.7, intern...
CVE-2026-67185HIGH8.7TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary fi...
CVE-2026-67184HIGH8.7TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to ...
CVE-2026-67183HIGH8.7TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available me...
CVE-2026-67182HIGH7.5Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to bypass acce...
CVE-2026-54620LOW2sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite agg...
CVE-2026-54619LOW2sqlite3 provides Ruby bindings for the SQLite3 embedded database. In version 2.9.4 and earlier, redefining a SQLite func...