CVE Vulnerability Database

Search and browse 376,099 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-68872MEDIUM6.5The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team...
CVE-2026-68871MEDIUM6.5The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id ...
CVE-2026-68870MEDIUM5.3The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Va...
CVE-2026-59091HIGH7.3A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit t...
CVE-2026-12339MEDIUM6.9A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive contai...
CVE-2026-72900HIGH7.1Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.
CVE-2026-72899CRITICAL10Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes...
CVE-2026-72898CRITICAL10Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint a...
CVE-2026-72862CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, pos...
CVE-2026-72740CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git...
CVE-2026-72739MEDIUM6.5Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs...
CVE-2026-72738CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoin...
CVE-2026-72737CRITICAL9.6Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and ...
CVE-2026-72736CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values d...
CVE-2026-72735CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/se...
CVE-2026-72734HIGH8.4Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutatio...
CVE-2026-72733CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC s...
CVE-2026-72732MEDIUM4.3Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse_temp...
CVE-2026-70622HIGH7.1tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function t...
CVE-2026-48159CRITICAL9.3use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the def...
CVE-2026-16626CRITICAL9.3Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server...
CVE-2026-10754HIGH8.6Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may ...
CVE-2026-72731HIGH7.1Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-l...
CVE-2026-72730HIGH8.7Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Edit...
CVE-2026-72729LOW2Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-loca...