CVE Vulnerability Database
Search and browse 383,924 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-66030 | MEDIUM | 5.4 | 0.2% | Jul 27, 2026 | Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authen... |
| CVE-2026-66029 | MEDIUM | 5.4 | 0.2% | Jul 27, 2026 | Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent... |
| CVE-2026-66028 | HIGH | 7.1 | 0.3% | Jul 27, 2026 | Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authe... |
| CVE-2026-64645 | MEDIUM | 6.1 | 1.0% | Jul 27, 2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr... |
| CVE-2026-64644 | MEDIUM | 5.3 | 0.5% | Jul 27, 2026 | Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 thr... |
| CVE-2026-64643 | MEDIUM | 5.3 | 0.7% | Jul 27, 2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr... |
| CVE-2026-64642 | HIGH | 8.2 | 1.3% | Jul 27, 2026 | Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted reque... |
| CVE-2026-64641 | HIGH | 7.5 | 0.5% | Jul 27, 2026 | Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 thr... |
| CVE-2026-59239 | HIGH | 8.6 | — | Jul 27, 2026 | Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authe... |
| CVE-2026-55579 | CRITICAL | 9.8 | — | Jul 27, 2026 | Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor s... |
| CVE-2026-55578 | HIGH | 8.8 | 0.4% | Jul 27, 2026 | Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, the termin... |
| CVE-2026-54540 | HIGH | 8.8 | — | Jul 27, 2026 | Pheditor is a single-file editor and file manager written in PHP. Prior to version 2.0.5, there is an authenticated term... |
| CVE-2026-54272 | MEDIUM | 6.9 | — | Jul 27, 2026 | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2... |
| CVE-2026-51235 | — | — | 0.3% | Jul 27, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-48052 | MEDIUM | 5.4 | 0.2% | Jul 27, 2026 | Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who i... |
| CVE-2026-48051 | LOW | 3.5 | 0.2% | Jul 27, 2026 | Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, Papra's webhook delivery sy... |
| CVE-2026-48030 | CRITICAL | 9.9 | — | Jul 27, 2026 | Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Comm... |
| CVE-2026-45623 | CRITICAL | 9.1 | 0.5% | Jul 27, 2026 | PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract ... |
| CVE-2026-17570 | MEDIUM | 4.3 | 0.2% | Jul 27, 2026 | Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileg... |
| CVE-2026-17569 | MEDIUM | 4.3 | 0.2% | Jul 27, 2026 | Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only per... |
| CVE-2026-17568 | HIGH | 8.8 | 0.2% | Jul 27, 2026 | Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-adm... |
| CVE-2026-17552 | CRITICAL | 9.1 | 0.2% | Jul 27, 2026 | Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concaten... |
| CVE-2026-66731 | HIGH | 8.7 | 0.5% | Jul 27, 2026 | facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser... |
| CVE-2026-66730 | HIGH | 8.7 | 0.5% | Jul 27, 2026 | facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unau... |
| CVE-2026-66729 | HIGH | 8.7 | 0.5% | Jul 27, 2026 | facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows u... |
