CVE Vulnerability Database

Search and browse 389,869 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-64625CRITICAL9.8AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-q...
CVE-2026-64624HIGH8.5FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the e...
CVE-2026-57852MEDIUM6.3Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote att...
CVE-2026-57495HIGH8.2AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, ...
CVE-2026-57494HIGH7.1AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-p...
CVE-2026-55550HIGH7.1NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide ...
CVE-2026-55544HIGH7.6NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose...
CVE-2026-52656CRITICAL9.8An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an a...
CVE-2026-51385MEDIUM6.9An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code v...
CVE-2026-51031HIGH7.5FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. T...
CVE-2026-51025MEDIUM6.1Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary...
CVE-2026-47255HIGH8.2AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenti...
CVE-2026-47144MEDIUM5.5Shamefile is a linter for undocumented linter warnings. Prior to version 0.1.7, a path traversal vulnerability in `shame...
CVE-2026-47134MEDIUM6.9ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. The ECDSA private k...
CVE-2026-47133MEDIUM6.9ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 5....
CVE-2026-47128MEDIUM6.1nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landloc...
CVE-2026-44510Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a ...
CVE-2026-16324HIGH7.3A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function ...
CVE-2026-12900MEDIUM6.4The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2024-51316HIGH7.5The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /g...
CVE-2024-51315CRITICAL9.8The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/Se...
CVE-2024-51314CRITICAL9.8The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/se...
CVE-2024-51312CRITICAL9.8The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/Se...
CVE-2026-64651MEDIUM6.3The `@ai-sdk/harness-opencode` tool connects HarnessAgent to OpenCode through a sandboxed bridge. Prior to version 1.0.2...
CVE-2026-64650MEDIUM6.3The `@ai-sdk/harness-opencode` tool is an HarnessV1 adapter backed by @openai/codex-sdk, which drives the codex command ...