CVE Vulnerability Database

Search and browse 386,125 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-65760CRITICAL9.2Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0...
CVE-2026-65759HIGH8.7Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical...
CVE-2026-65698MEDIUM6Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjace...
CVE-2026-65697MEDIUM6.1Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that...
CVE-2026-65696MEDIUM5.4Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscrip...
CVE-2026-65695HIGH7.6Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attacker...
CVE-2026-44909HIGH7.5Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticate...
CVE-2026-16768MEDIUM5.3A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined pale...
CVE-2026-65917HIGH8.8CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in ...
CVE-2026-65916HIGH8.1CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCre...
CVE-2026-48539MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report conf...
CVE-2026-48538MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configurat...
CVE-2026-48537MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configurati...
CVE-2026-48536MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuratio...
CVE-2026-48535MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configurati...
CVE-2026-48534MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that all...
CVE-2026-48533Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-48532MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy conf...
CVE-2026-48531MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration tha...
CVE-2026-48530MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration...
CVE-2026-16584HIGH7.3Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to ...
CVE-2026-15617CRITICAL9.1Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unaut...
CVE-2026-15616CRITICAL9.1Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirem...
CVE-2026-15615HIGH7.5Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and ...
CVE-2026-15614HIGH7.5Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s valid...