CVE Vulnerability Database

Search and browse 376,099 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-22652Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-22651Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-12624MEDIUM4.3Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a tra...
CVE-2026-72726MEDIUM6.5Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated u...
CVE-2026-72725MEDIUM5.4Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previo...
CVE-2026-72724MEDIUM4.3Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, plugins/chat/lib/c...
CVE-2026-72723MEDIUM5.3Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.ano...
CVE-2026-72722MEDIUM4.3Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, TopicLink.extract_...
CVE-2026-72721MEDIUM5.3Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Onebox::DomainChec...
CVE-2026-72720MEDIUM6.4Discourse is an open-source discussion platform. Prior to 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, Discourse...
CVE-2026-72719MEDIUM6.7Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transf...
CVE-2026-72718HIGH7goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system...
CVE-2026-66738HIGH8.8SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint ...
CVE-2026-56620MEDIUM4.3HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error repor...
CVE-2026-48158CRITICAL9.3use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34,...
CVE-2026-48048HIGH7.5XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Sta...
CVE-2026-47754CRITICAL9.3Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19...
CVE-2026-72761MEDIUM6.9The webhook URL validator in `website/notifications/webhooks.py` uses `ip.is_global` to reject non-public addresses afte...
CVE-2026-72760MEDIUM5.3Affected versions of MISP cti-transmute disclose users' email addresses through the account following-list endpoint. Whe...
CVE-2026-72759MEDIUM6.9In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization...
CVE-2026-19433HIGH8.6Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before ...
CVE-2026-18412CRITICAL9.1OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 exten...
CVE-2026-72751MEDIUM5.1CTI-Transmute is affected by a stored cross-site scripting (XSS) vulnerability in the conversion graph used to visualise...
CVE-2026-71959MEDIUM5.8Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /c...
CVE-2026-63106CRITICAL9.8ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the...