CVE Vulnerability Database

Search and browse 389,948 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-38752LOW2.9A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial ...
CVE-2026-36590HIGH7.5An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in...
CVE-2026-30623CRITICAL9.8LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application...
CVE-2026-30618CRITICAL9.8xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution...
CVE-2026-26719MEDIUM6.1Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a cra...
CVE-2026-26718CRITICAL9.1A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an att...
CVE-2026-15921LOW3.1Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js versions. In versions 0.32....
CVE-2025-65720CRITICAL9.8An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user...
CVE-2026-62361MEDIUM5.5listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to 6.2.0, listmonk’s GET /api/subscrib...
CVE-2026-62312HIGH8.89Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacker to achieve arbitra...
CVE-2026-59950HIGH8.1The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1,...
CVE-2026-56679HIGH8.79Router is an AI router & token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the entire request body t...
CVE-2026-56678MEDIUM6.49Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key...
CVE-2026-55608MEDIUM5.4n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior...
CVE-2026-55410MEDIUM6.7NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t...
CVE-2026-55399MEDIUM4.3CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with vali...
CVE-2026-55398LOW3.7CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14.55. Attackers with ...
CVE-2026-54052CRITICAL9.9n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior...
CVE-2026-52888MEDIUM6.8NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0....
CVE-2026-52887CRITICAL10NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t...
CVE-2026-51380CRITICAL9.8Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of S...
CVE-2026-49353HIGH7.59Router is an AI router & token saver. In 0.4.45 and earlier, 9Router's src/dashboardGuard.js local-only access gate use...
CVE-2026-49352CRITICAL9.89Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-...
CVE-2026-46339CRITICAL109Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/...
CVE-2026-38753MEDIUM4.9A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Serv...