CVE Vulnerability Database

Search and browse 386,644 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-65058MEDIUM5.9Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip155...
CVE-2026-65057CRITICAL9.3Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make...
CVE-2026-65056HIGH8.3mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal netw...
CVE-2026-65055MEDIUM6.9Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full m...
CVE-2026-65054HIGH8.2MediaCMS 8.2.0 contains an information disclosure vulnerability that allows authenticated users to expose private media ...
CVE-2026-64881HIGH8.8The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command exe...
CVE-2026-64822MEDIUM6.9djangoSIGE through 1.10 (commit a6fe7e8) contains a user enumeration vulnerability in ForgotPasswordView within djangosi...
CVE-2026-64821MEDIUM5.3djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that allows unauthenticated...
CVE-2026-63764HIGH8.6LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _lo...
CVE-2026-63358HIGH8.4FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to P...
CVE-2026-63140MEDIUM6.5Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A ...
CVE-2026-63139MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)...
CVE-2026-63136MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP...
CVE-2026-63092MEDIUM5.3kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any a...
CVE-2026-63080HIGH7.1Aptabase through commit 5a89368 contains a SQL injection vulnerability in the ClickHouse query backend that allows authe...
CVE-2026-56147HIGH7.1Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and...
CVE-2026-52476HIGH7.5SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the getPage...
CVE-2026-52475MEDIUM6.1Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the ...
CVE-2026-52474HIGH7.5An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUtil.java file.
CVE-2026-52472CRITICAL9.8SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml ...
CVE-2026-52470CRITICAL9.8SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper...
CVE-2026-52469CRITICAL9.8SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper....
CVE-2026-47714MEDIUM6.1libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code i...
CVE-2026-47708CRITICAL9.3MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` ...
CVE-2026-47697HIGH7.1Shelf is a platform for tracking physical assets. Shelf is multi-tenant; data is isolated per organization (workspace). ...