CVE Vulnerability Database

Search and browse 384,615 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-65919HIGH8.7Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api...
CVE-2026-65918HIGH7.1PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GI...
CVE-2026-65763MEDIUM5.1Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs...
CVE-2026-65762MEDIUM5.1Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user i...
CVE-2026-65702HIGH8.6Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration t...
CVE-2026-65701CRITICAL9.3SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inf...
CVE-2026-65700CRITICAL9.8h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthentica...
CVE-2026-65699MEDIUM4.2AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authentica...
CVE-2026-47769MEDIUM5.3APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Pr...
CVE-2026-47755MEDIUM6.5ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi...
CVE-2026-47752CRITICAL9.9Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to S...
CVE-2026-47743HIGH8.7Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed...
CVE-2026-47668CRITICAL10DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/star...
CVE-2026-44210CRITICAL9.9Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th...
CVE-2026-65761CRITICAL9.3Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validat...
CVE-2026-65760CRITICAL9.2Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0...
CVE-2026-65759HIGH8.7Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical...
CVE-2026-65698MEDIUM6Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjace...
CVE-2026-65697MEDIUM6.1Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that...
CVE-2026-65696MEDIUM5.4Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscrip...
CVE-2026-65695HIGH7.6Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attacker...
CVE-2026-44909HIGH7.5Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticate...
CVE-2026-16768MEDIUM5.3A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined pale...
CVE-2026-65917HIGH8.8CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in ...
CVE-2026-65916HIGH8.1CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCre...