CVE Vulnerability Database

Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-48010MEDIUM6.5Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framewo...
CVE-2026-48009MEDIUM6.8Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:re...
CVE-2026-48008MEDIUM6.5Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL...
CVE-2025-59866LOW3.3The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Es...
CVE-2026-9588HIGH7A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicem...
CVE-2026-9587HIGH7.1An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file ...
CVE-2026-9586CRITICAL9.8An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint pr...
CVE-2026-9585HIGH8.6An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8....
CVE-2026-8297CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics En...
CVE-2026-63309MEDIUM4.3SurrealDB before 3.1.5 fail to apply field-level SELECT permissions to ORDER BY clauses, allowing authenticated users to...
CVE-2026-63308MEDIUM6.5Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template help...
CVE-2026-63307HIGH7.1Chat2DB before 5.3.0 contains an insecure direct object reference vulnerability in the GET /api/connection/datasource/{i...
CVE-2026-63101HIGH8.7Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers t...
CVE-2026-57860HIGH7.8ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined i...
CVE-2026-54496CRITICAL9.3ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primit...
CVE-2026-49216MEDIUM5.4Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/...
CVE-2026-49215MEDIUM5.4Symfony UX is a JavaScript ecosystem for Symfony. From 2.22.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\EventList...
CVE-2026-49212HIGH7.5Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\UX\Liv...
CVE-2026-49211HIGH7.5Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, Symfony\UX\Autocomplete\Doctrine\En...
CVE-2026-49210MEDIUM6.1Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\Child...
CVE-2026-49209MEDIUM6.5Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller...
CVE-2026-49208MEDIUM5.3Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as Date...
CVE-2026-44722MEDIUM6.2pyzipper is a replacement for Python's zipfile that can read and write AES encrypted zip files. Prior to 0.4.0, a Python...
CVE-2026-21764MEDIUM4.3HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restric...
CVE-2026-21762MEDIUM5.3HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections ag...