CVE Vulnerability Database

Search and browse 383,924 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-66030MEDIUM5.4Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authen...
CVE-2026-66029MEDIUM5.4Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent...
CVE-2026-66028HIGH7.1Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authe...
CVE-2026-64645MEDIUM6.1Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-64644MEDIUM5.3Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-64643MEDIUM5.3Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-64642HIGH8.2Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted reque...
CVE-2026-64641HIGH7.5Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-59239HIGH8.6Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authe...
CVE-2026-55579CRITICAL9.8Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor s...
CVE-2026-55578HIGH8.8Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, the termin...
CVE-2026-54540HIGH8.8Pheditor is a single-file editor and file manager written in PHP. Prior to version 2.0.5, there is an authenticated term...
CVE-2026-54272MEDIUM6.9ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2...
CVE-2026-51235Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-48052MEDIUM5.4Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who i...
CVE-2026-48051LOW3.5Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, Papra's webhook delivery sy...
CVE-2026-48030CRITICAL9.9Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Comm...
CVE-2026-45623CRITICAL9.1PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract ...
CVE-2026-17570MEDIUM4.3Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileg...
CVE-2026-17569MEDIUM4.3Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only per...
CVE-2026-17568HIGH8.8Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-adm...
CVE-2026-17552CRITICAL9.1Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concaten...
CVE-2026-66731HIGH8.7facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser...
CVE-2026-66730HIGH8.7facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unau...
CVE-2026-66729HIGH8.7facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows u...