CVE Vulnerability Database
Search and browse 376,099 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-68872 | MEDIUM | 6.5 | 0.2% | Aug 10, 2026 | The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team... |
| CVE-2026-68871 | MEDIUM | 6.5 | 0.1% | Aug 10, 2026 | The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id ... |
| CVE-2026-68870 | MEDIUM | 5.3 | 0.1% | Aug 10, 2026 | The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Va... |
| CVE-2026-59091 | HIGH | 7.3 | 0.2% | Aug 10, 2026 | A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit t... |
| CVE-2026-12339 | MEDIUM | 6.9 | 0.3% | Aug 10, 2026 | A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive contai... |
| CVE-2026-72900 | HIGH | 7.1 | — | Aug 10, 2026 | Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database. |
| CVE-2026-72899 | CRITICAL | 10 | — | Aug 10, 2026 | Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes... |
| CVE-2026-72898 | CRITICAL | 10 | 1.1% | Aug 10, 2026 | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint a... |
| CVE-2026-72862 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, pos... |
| CVE-2026-72740 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git... |
| CVE-2026-72739 | MEDIUM | 6.5 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs... |
| CVE-2026-72738 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoin... |
| CVE-2026-72737 | CRITICAL | 9.6 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and ... |
| CVE-2026-72736 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values d... |
| CVE-2026-72735 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/se... |
| CVE-2026-72734 | HIGH | 8.4 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutatio... |
| CVE-2026-72733 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC s... |
| CVE-2026-72732 | MEDIUM | 4.3 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse_temp... |
| CVE-2026-70622 | HIGH | 7.1 | — | Aug 10, 2026 | tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function t... |
| CVE-2026-48159 | CRITICAL | 9.3 | — | Aug 10, 2026 | use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the def... |
| CVE-2026-16626 | CRITICAL | 9.3 | 0.3% | Aug 10, 2026 | Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server... |
| CVE-2026-10754 | HIGH | 8.6 | 0.6% | Aug 10, 2026 | Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may ... |
| CVE-2026-72731 | HIGH | 7.1 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-l... |
| CVE-2026-72730 | HIGH | 8.7 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Edit... |
| CVE-2026-72729 | LOW | 2 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-loca... |
