CVE Vulnerability Database

Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-45325HIGH8.2Gestor de Oferta is a web application for managing mobility service offerings. Prior to 20260509.0340.15, @tmlmobilidade...
CVE-2026-44632CRITICAL9.1Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs a...
CVE-2026-44596CRITICAL9.8Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handl...
CVE-2026-44595MEDIUM4.3Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGrou...
CVE-2026-3031CRITICAL9.8Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg...
CVE-2026-14371HIGH8.8The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vul...
CVE-2026-13401HIGH7.5XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_p...
CVE-2026-13397HIGH7.5HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_...
CVE-2026-13104HIGH7.3A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could al...
CVE-2026-13103HIGH7.3A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market...
CVE-2026-10590MEDIUM6.7A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrar...
CVE-2026-10589MEDIUM6.8A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Manageme...
CVE-2026-10588MEDIUM6.7A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management...
CVE-2026-10587MEDIUM6.8A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management setting...
CVE-2025-45870MEDIUM6.5LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet c...
CVE-2026-63082MEDIUM5.4Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that a...
CVE-2026-63081MEDIUM5.4Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability ...
CVE-2026-59867HIGH7.1Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota resolved OpenAPI $ref values by ...
CVE-2026-59866CRITICAL9.3Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota emitted x-ms-kiota-info clientCl...
CVE-2026-59865CRITICAL9.3Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota info` read x-ms-kiota-info.lang...
CVE-2026-59864CRITICAL9.3Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota plugin add` and `kiota plugin g...
CVE-2026-57206HIGH8.6SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions...
CVE-2026-57205MEDIUM4.3SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions...
CVE-2026-55440MEDIUM6.5Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND...
CVE-2026-54733CRITICAL9.3The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration fo...