CVE Vulnerability Database

Search and browse 375,982 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-72913HIGH7.3Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/wind...
CVE-2026-72912MEDIUM4.3CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-rec...
CVE-2026-72911CRITICAL9.9ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_templat...
CVE-2026-72910HIGH7.1ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, p...
CVE-2026-72909HIGH7.1ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayabl...
CVE-2026-72908MEDIUM6.5ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template...
CVE-2026-72907MEDIUM6.5ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function ...
CVE-2026-72906MEDIUM4.3ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email ...
CVE-2026-72905Rejected reason: Further research determined the issue is not a vulnerability.
CVE-2026-72904CRITICAL9.3Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file ...
CVE-2026-72903HIGH8.1Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can retu...
CVE-2026-72743MEDIUM5.4SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashb...
CVE-2026-63622HIGH7.8A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploi...
CVE-2026-48160CRITICAL9.3react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the defau...
CVE-2026-19411LOW3.9A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could al...
CVE-2026-18982HIGH8.8A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in a...
CVE-2026-18951HIGH8.8A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly ag...
CVE-2026-18950HIGH8.8A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how Rol...
CVE-2026-18949HIGH8.8A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Ac...
CVE-2026-18948CRITICAL9.9A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, whic...
CVE-2026-18947HIGH8.5A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental...
CVE-2026-18942MEDIUM5.5A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. Th...
CVE-2026-18941HIGH7.7A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is...
CVE-2026-18621HIGH7.6A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security harde...
CVE-2026-18620HIGH7.1A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerab...