CVE Vulnerability Database

Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-47088LOW3.1An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsi...
CVE-2026-47087LOW3.5An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A...
CVE-2026-47086LOW3.5An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authe...
CVE-2026-47085MEDIUM4An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxk...
CVE-2026-47084MEDIUM6.5An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An aut...
CVE-2026-47083MEDIUM4.3An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By u...
CVE-2026-47082MEDIUM5.4An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-ma...
CVE-2026-47081LOW3.1An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence orac...
CVE-2026-46515CRITICAL9.3Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call ...
CVE-2026-46514MEDIUM6.5Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_reset_password in Tools/ResetPassword...
CVE-2026-46513HIGH7.4Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, Frogman stored API tokens generated by T...
CVE-2026-46512CRITICAL9.9Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template para...
CVE-2026-46404MEDIUM6.8BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly res...
CVE-2026-46378MEDIUM6.2Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1...
CVE-2026-46377MEDIUM6.2Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1...
CVE-2026-46353HIGH8.1BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a...
CVE-2026-46351HIGH8.1BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values wit...
CVE-2026-46338MEDIUM4.3PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx....
CVE-2026-46687HIGH7.7Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-t...
CVE-2026-46686HIGH8.5Emlog is an open source website building system. In 2.6.13 and earlier, the admin backend user search module's keyword p...
CVE-2026-46341MEDIUM6.1The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation...
CVE-2026-46336HIGH7.1Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on ...
CVE-2026-45336CRITICAL10HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring ...
CVE-2026-44970MEDIUM4.3dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DefaultUsageTracker.emit_tool_call...
CVE-2026-44969LOW3.3dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/...