CVE Vulnerability Database

Search and browse 383,933 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-48030CRITICAL9.9Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Comm...
CVE-2026-45623CRITICAL9.1PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract ...
CVE-2026-17570MEDIUM4.3Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileg...
CVE-2026-17569MEDIUM4.3Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only per...
CVE-2026-17568HIGH8.8Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-adm...
CVE-2026-17552CRITICAL9.1Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concaten...
CVE-2026-66731HIGH8.7facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser...
CVE-2026-66730HIGH8.7facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unau...
CVE-2026-66729HIGH8.7facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows u...
CVE-2026-66391MEDIUM6.5Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Ap...
CVE-2026-66390MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. Th...
CVE-2026-63077CRITICAL9.8In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin...
CVE-2026-24252HIGH7.8NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of...
CVE-2026-17531MEDIUM5A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality...
CVE-2026-17192HIGH8.5A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authentica...
CVE-2026-17191CRITICAL9.1An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this...
CVE-2026-66399HIGH8.5phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows admi...
CVE-2026-66398CRITICAL9.4phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated...
CVE-2026-66397HIGH8.6phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, al...
CVE-2026-66396CRITICAL9.3SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cov...
CVE-2026-66395CRITICAL9.6SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler...
CVE-2026-66394CRITICAL9.3SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows ...
CVE-2026-59251HIGH7.5Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthentica...
CVE-2026-59250HIGH8.3Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corru...
CVE-2026-58227HIGH7.5The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a ...