CVE Vulnerability Database

Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-15007MEDIUM5.7A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause...
CVE-2026-14871HIGH7.1osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Obje...
CVE-2026-14741HIGH7.5HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date. parse_da...
CVE-2026-12715HIGH8.5Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an at...
CVE-2026-63094HIGH8.1SigNoz before 0.134.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated...
CVE-2026-63093HIGH8.8Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbit...
CVE-2026-51083MEDIUM6.5Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows u...
CVE-2026-51082HIGH7.2A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager be...
CVE-2026-51081MEDIUM6.1A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environmen...
CVE-2026-16089MEDIUM5.9A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 aut...
CVE-2026-16017MEDIUM6.3A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. Impacted is the function list/remove of the file to...
CVE-2026-12705MEDIUM6.4Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE). This issue a...
CVE-2026-9592HIGH7.5SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user sess...
CVE-2026-7488HIGH7.5Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embed...
CVE-2026-51080CRITICAL9.8libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnera...
CVE-2026-16072MEDIUM4.9A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to mana...
CVE-2026-16016HIGH7.3A vulnerability was identified in poco-ai poco-claw up to 0.5.4. This issue affects the function run_task of the file ex...
CVE-2026-16015MEDIUM6.3A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of ...
CVE-2025-60357HIGH8.1AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEv...
CVE-2024-42214MEDIUM5.3HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method ...
CVE-2024-23578MEDIUM4.2HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) ...
CVE-2024-23577MEDIUM4.3HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary...
CVE-2024-23575MEDIUM5.3HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information ...
CVE-2024-23574MEDIUM5.3HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to ...
CVE-2024-23573LOW3.7HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 ...