CVE Vulnerability Database

Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-16082MEDIUM5.3A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun ...
CVE-2026-16081MEDIUM4.3A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file w...
CVE-2026-16077MEDIUM5.3A vulnerability was found in AstrBotDevs AstrBot up to 4.25.5. Impacted is the function _normalize_rw_path of the file a...
CVE-2026-16076MEDIUM6.3A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function OpenApiRoute.chat_se...
CVE-2026-9734MEDIUM4.3The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2026-16075MEDIUM4.3A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. This vulnerability affects the function OpenApiRoute.get_chat...
CVE-2026-57980MEDIUM5.4Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attac...
CVE-2026-56741HIGH7.5JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote...
CVE-2026-56740HIGH7.5JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote...
CVE-2026-56171HIGH7.5Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disc...
CVE-2026-54335LOW3.7Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In 5.0.44 and ...
CVE-2026-49485HIGH7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.9 ...
CVE-2026-48049MEDIUM5.3@hapi/inert provides static file and directory handlers for hapi.js. From 4.0.0 to 7.1.0, @hapi/inert serves static file...
CVE-2026-48022MEDIUM6.5@hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie,...
CVE-2026-44979MEDIUM6.3@hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname,...
CVE-2026-55518CRITICAL9.6Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association a...
CVE-2026-54498HIGH8.7view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4...
CVE-2026-54497MEDIUM6.8view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4...
CVE-2026-54490MEDIUM6.3websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, if this library is used with the pe...
CVE-2026-54466HIGH7.5websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions ...
CVE-2026-54244LOW3.5Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endp...
CVE-2026-54243MEDIUM6.1Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, form submission valu...
CVE-2026-54242MEDIUM4.9Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, the Glide image prox...
CVE-2026-54163MEDIUM4.7secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds th...
CVE-2026-54159CRITICAL10PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsear...