CVE Vulnerability Database

Search and browse 389,905 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-26197HIGH7.5HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If a file is cor...
CVE-2026-26081MEDIUM4.8HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise...
CVE-2026-26080LOW3.7HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAPro...
CVE-2026-25039HIGH8.8Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanit...
CVE-2026-21824HIGH8.8HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user perso...
CVE-2026-13724MEDIUM4.3Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry an...
CVE-2026-63091HIGH7.1ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-r...
CVE-2026-63090HIGH8.8ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allo...
CVE-2026-63071CRITICAL9.8Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements...
CVE-2026-62418HIGH8.1Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Reso...
CVE-2026-62183CRITICAL9.8Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configure...
CVE-2026-59238MEDIUM6.9Stored Cross-site Scripting (CWE-79) in the client-side report rendering functions (renderPreview, renderEditor, renderA...
CVE-2026-57308CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. A...
CVE-2026-54910HIGH7.7FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` ...
CVE-2026-54685MEDIUM5.3FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` a...
CVE-2026-53421CRITICAL9.8Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlemen...
CVE-2026-53405CRITICAL9.8Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements...
CVE-2026-52349HIGH7.8Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local a...
CVE-2026-51386Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2026-46409. Reason: This record is a reservation duplicate ...
CVE-2026-46516MEDIUM4.8Frogman provides headless FreePBX control. Prior to version 1.6.6, Frogman's chat-console markdown formatter (`assets/js...
CVE-2026-46410HIGH8.7FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may le...
CVE-2026-45270HIGH8.7CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module...
CVE-2026-45139MEDIUM6.5CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enfo...
CVE-2026-16277MEDIUM6.5A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcin...
CVE-2026-16252HIGH7.3A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System ...