CVE Vulnerability Database

Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-54568MEDIUM4.3Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a c...
CVE-2026-53598HIGH7.5Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:......
CVE-2026-53597HIGH8.7Prompty is a markdown file format (.prompty) for LLM prompts. From 2.0.0-alpha.1 until 2.0.0-beta.3, the @prompty/core T...
CVE-2026-45695CRITICAL9.8Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-en...
CVE-2026-14890CRITICAL9.1SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that d...
CVE-2026-12379MEDIUM6.8An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC authentication implementation of the Axivion Dashboard...
CVE-2025-45868HIGH8.8LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allo...
CVE-2026-59863HIGH7Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota honored a poisoned .kiota/worksp...
CVE-2026-59862HIGH7.5Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Python generator let attacker-...
CVE-2026-59861HIGH7.5Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Ruby generator embedded OpenAP...
CVE-2026-59860HIGH8.7Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.3, Kiota is affected by a code-generation...
CVE-2026-59859HIGH8.7Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.4, Kiota's PHP generator embedded OpenAPI...
CVE-2026-59237MEDIUM6.9Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Pro...
CVE-2026-14254HIGH8.3A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed...
CVE-2026-5674HIGH8.8A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed application...
CVE-2026-56456MEDIUM5.3HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently ...
CVE-2026-56455HIGH7.5HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The applicat...
CVE-2026-56454HIGH7.5HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy ...
CVE-2026-56453CRITICAL9.8HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can inter...
CVE-2026-35145LOW3.1HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to ...
CVE-2026-35143MEDIUM6.5HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" ...
CVE-2026-35142HIGH8.2HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP ad...
CVE-2026-35141MEDIUM5.3HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to interce...
CVE-2026-35140HIGH7.2HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The applicat...
CVE-2026-9494MEDIUM5.5An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The cli...