CVE Vulnerability Database

Search and browse 375,948 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-72561HIGH8.8A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-a...
CVE-2026-72560MEDIUM6.5A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTI...
CVE-2026-72559MEDIUM5.4A stored cross-site scripting vulnerability in HortusFox 5.9 allows authenticated workspace members to inject persistent...
CVE-2026-72558HIGH8.8An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via...
CVE-2026-72557HIGH8.8An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extensi...
CVE-2026-72556HIGH8.8A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands by expl...
CVE-2026-72555HIGH8.1A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.role...
CVE-2026-72554MEDIUM6.5A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer ...
CVE-2026-72553MEDIUM5.4A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows any registered member to inject persisten...
CVE-2026-72552HIGH7.5A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the ...
CVE-2026-72551HIGH8.8A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with the Developer role to execute...
CVE-2026-72550CRITICAL9.8An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to ex...
CVE-2026-72549MEDIUM5.3An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers ...
CVE-2026-72548HIGH7.5An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers ...
CVE-2026-72547HIGH7.1An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event org...
CVE-2026-72546HIGH7.1An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event org...
CVE-2026-72545HIGH7.5An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote ...
CVE-2026-72544HIGH7.5An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers ...
CVE-2026-72543HIGH7.5An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote ...
CVE-2026-72542MEDIUM5.4A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write ...
CVE-2026-72541MEDIUM6.5A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace membe...
CVE-2026-72540MEDIUM4.3An insecure direct object reference vulnerability in PhotoPrism through commit bb0b933 allows any user with a valid prev...
CVE-2026-72539MEDIUM6.5An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace mem...
CVE-2026-72538HIGH8.8An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code...
CVE-2026-72537HIGH8.8A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-s...