CVE Vulnerability Database

Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-53727HIGH8.6css_parser is a Ruby CSS parser. From 2.2.0 until 3.0.0, CssParser::Parser#read_remote_file in lib/css_parser/parser.rb,...
CVE-2026-52584HIGH7.1Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensitive information via ...
CVE-2026-52348CRITICAL9.8cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.
CVE-2026-52203HIGH7.5An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter.
CVE-2026-50274HIGH7.5Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling, and security monit...
CVE-2026-50272HIGH7.5dd-trace is the Datadog APM client for Node.js. Prior to 5.100.0, W3C baggage propagation in packages/dd-trace/src/bagga...
CVE-2026-50271HIGH7.5Datadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that implement W3C bagga...
CVE-2026-49977MEDIUM4.3tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.33.0, tarteaucitron.cookie.purge() is called on...
CVE-2026-48062CRITICAL9.8CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/St...
CVE-2026-45785MEDIUM6.2OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Sto...
CVE-2026-45784HIGH7.1rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::ciph...
CVE-2026-44891HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2...
CVE-2026-16074MEDIUM6.3A vulnerability was detected in AstrBotDevs AstrBot up to 4.25.2. This affects the function update_plugin/update_all_plu...
CVE-2026-13446CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it...
CVE-2026-13445HIGH8.1IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read an...
CVE-2026-8861MEDIUM5.3IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error messag...
CVE-2026-8859CRITICAL9.9IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations ...
CVE-2026-8635CRITICAL9.9IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipul...
CVE-2026-8505CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthentica...
CVE-2026-8481CRITICAL9.9IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API ...
CVE-2026-8476CRITICAL9.9IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching m...
CVE-2026-8056HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API...
CVE-2026-7872HIGH8.1IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing...
CVE-2026-7771MEDIUM5.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted stat...
CVE-2026-7755HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcemen...