CVE Vulnerability Database

Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-21761MEDIUM5.4HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may ...
CVE-2026-21760MEDIUM4.6HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper a...
CVE-2026-16108MEDIUM6.5A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible...
CVE-2026-16106MEDIUM4.9A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when...
CVE-2026-16104MEDIUM6.5A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engi...
CVE-2026-16103MEDIUM4.3A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, wher...
CVE-2026-16093MEDIUM5.4Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them...
CVE-2026-12694CRITICAL9.1Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Proper...
CVE-2026-12693CRITICAL9.4Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessi...
CVE-2026-12692CRITICAL9.8Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This ...
CVE-2026-12691HIGH7.5Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authenticat...
CVE-2026-11763MEDIUM6.5Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D ...
CVE-2026-9537MEDIUM5.3Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode()...
CVE-2026-63100HIGH7.1Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role u...
CVE-2026-63099HIGH7.1TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints t...
CVE-2026-63098MEDIUM6.9TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated atta...
CVE-2026-63097MEDIUM5.3Dendrite through 0.13.8 contains an improper access control vulnerability in the syncapi /context endpoint (syncapi/rout...
CVE-2026-63096MEDIUM6.9Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to ca...
CVE-2026-63095HIGH7.1Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any...
CVE-2026-60025HIGH8.8Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking p...
CVE-2026-60024CRITICAL9.8Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Event...
CVE-2026-58149MEDIUM5.3Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking i...
CVE-2026-58148HIGH8.7Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension...
CVE-2026-15783MEDIUM5.3A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with...
CVE-2026-15343HIGH8.6A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code executio...