CVE Vulnerability Database

Search and browse 375,982 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-72761MEDIUM6.9The webhook URL validator in `website/notifications/webhooks.py` uses `ip.is_global` to reject non-public addresses afte...
CVE-2026-72760MEDIUM5.3Affected versions of MISP cti-transmute disclose users' email addresses through the account following-list endpoint. Whe...
CVE-2026-72759MEDIUM6.9In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization...
CVE-2026-19433HIGH8.6Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before ...
CVE-2026-18412CRITICAL9.1OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 exten...
CVE-2026-72751MEDIUM5.1CTI-Transmute is affected by a stored cross-site scripting (XSS) vulnerability in the conversion graph used to visualise...
CVE-2026-71959MEDIUM5.8Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /c...
CVE-2026-63106CRITICAL9.8ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the...
CVE-2026-63105MEDIUM5.4ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated custome...
CVE-2026-59112MEDIUM4.4Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability ...
CVE-2026-18503LOW2.4Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume si...
CVE-2026-18478MEDIUM5.1Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrar...
CVE-2026-16742MEDIUM6.7systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed...
CVE-2026-15060MEDIUM4.7When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running o...
CVE-2026-15059MEDIUM5.5Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traver...
CVE-2026-72692HIGH7.5A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote att...
CVE-2026-72691HIGH7.5An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote at...
CVE-2026-72690HIGH7.1An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacker to i...
CVE-2026-72689HIGH7.5A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticate...
CVE-2026-72688HIGH7.5A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote at...
CVE-2026-6374HIGH7.3Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive Constants Within an Executab...
CVE-2026-6373MEDIUM6.5Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allow...
CVE-2026-68428In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Fix use-after-free on vendor module r...
CVE-2026-68427In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix use-after-free in host1x_bo_clear_...
CVE-2026-68426In the Linux kernel, the following vulnerability has been resolved: xfrm: fix stale skb->prev after async crypto steals...