CVE Vulnerability Database

Search and browse 389,905 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-32819MEDIUM4.3dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat...
CVE-2026-32806HIGH7.5dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat...
CVE-2026-16312Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-6793MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering ...
CVE-2026-63429HIGH8.6HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no ...
CVE-2026-63428MEDIUM5.8HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id,...
CVE-2026-63102MEDIUM5.4rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitr...
CVE-2026-51027CRITICAL9.9An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.
CVE-2026-51026MEDIUM6.5Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a ...
CVE-2026-48824MEDIUM5.3Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2...
CVE-2026-46671MEDIUM4.4Rust OneNote File Parser is a parser for Microsoft OneNote files implemented in Rust. Prior to version 1.1.1, a maliciou...
CVE-2026-46428CRITICAL9.1lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug ...
CVE-2026-46415HIGH8.2The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the clien...
CVE-2026-46412CRITICAL10@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support...
CVE-2026-45797MEDIUM6.4HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, the `/api/upload` endpoint allows unauthenticated f...
CVE-2026-45713HIGH7.5Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.M...
CVE-2026-45712MEDIUM5.9Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?dat...
CVE-2026-45711HIGH8.2Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <ou...
CVE-2026-45709MEDIUM5.8Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side R...
CVE-2026-35198CRITICAL9HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability i...
CVE-2026-32822MEDIUM6.1dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat...
CVE-2026-32807HIGH7.5dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat...
CVE-2026-28220CRITICAL9.1Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, i...
CVE-2026-27823HIGH8.7A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an auth...
CVE-2026-26199MEDIUM6.5HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name`...