Browse vulnerabilities
378,245 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-85595 | High | 0.4% | 9.8 | Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentica… | |
| CVE-2026-34952 | High | 0.4% | 9.1 | PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway se… | |
| CVE-2026-8926 | High | 0.4% | 9.1 | When asking curl to use a `.netrc` file to find credentials and at the same time specifyin… | |
| CVE-2026-66898 | High | 0.4% | 9.9 | A path traversal vulnerability in LXD allows an attacker to manipulate file system paths d… | |
| CVE-2026-8983 | High | 0.4% | 9.8 | Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication t… | |
| CVE-2026-78676 | High | 0.4% | 9.8 | GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during w… | |
| CVE-2026-79675 | High | 0.4% | 9.8 | NLTK before 3.10.3 fails to validate JVM options passed through the per-call options param… | |
| CVE-2026-28802 | High | 0.4% | 9.8 | Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.… | |
| CVE-2026-28373 | High | 0.4% | 9.6 | The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal v… | |
| CVE-2026-51540 | High | 0.4% | 9.8 | OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corrupt… | |
| CVE-2026-51541 | High | 0.4% | 9.1 | OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when … | |
| CVE-2026-33950 | High | 0.4% | 9.4 | Signal K Server is a server application that runs on a central hub in a boat. Prior to ver… | |
| CVE-2026-34162 | High | 0.4% | 10.0 | FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tool… | |
| CVE-2026-44881 | High | 0.4% | 9.9 | Portainer Community Edition is a lightweight service delivery platform for containerized a… | |
| CVE-2026-49448 | High | 0.4% | 9.8 | authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and … | |
| CVE-2026-42601 | High | 0.4% | 9.8 | ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and pr… | |
| CVE-2026-63299 | High | 0.4% | 9.9 | An authorization bypass vulnerability in LXD allows an authenticated user to bypass projec… | |
| CVE-2025-70149 | High | 0.4% | 9.8 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_members… | |
| CVE-2026-38431 | High | 0.4% | 9.8 | ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An at… | |
| CVE-2025-52221 | High | 0.4% | 9.8 | Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function vi… | |
| CVE-2026-51538 | High | 0.4% | 9.1 | EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulne… | |
| CVE-2026-28798 | High | 0.4% | 9.0 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with U… | |
| CVE-2026-67324 | High | 0.4% | 9.8 | GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short… | |
| CVE-2026-31818 | High | 0.4% | 9.6 | Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side reque… | |
| CVE-2026-39397 | High | 0.4% | 9.4 | @delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page build… | |
| CVE-2026-34953 | High | 0.4% | 9.1 | PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_to… | |
| CVE-2026-34931 | High | 0.4% | 9.6 | hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there i… | |
| CVE-2026-62420 | High | 0.4% | 9.9 | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass ta… | |
| CVE-2026-38428 | High | 0.4% | 9.8 | Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because … | |
| CVE-2025-66024 | High | 0.4% | 9.0 | The XWiki blog application allows users of the XWiki platform to create and manage blog po… | |
| CVE-2026-11564 | High | 0.4% | 9.1 | libcurl keeps previously used connections in a connection pool for subsequent transfers to… | |
| CVE-2026-54526 | High | 0.4% | 9.9 | Argo Workflows is an open source container-native workflow engine for orchestrating parall… | |
| CVE-2026-48491 | High | 0.4% | 10.0 | Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a hig… | |
| CVE-2026-63300 | High | 0.4% | 9.9 | An improper validation vulnerability in the instancePostMigration function in lxd/instance… | |
| CVE-2026-35184 | High | 0.4% | 9.8 | EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injectio… | |
| CVE-2026-87528 | High | 0.3% | 9.6 | Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a rem… | |
| CVE-2026-34758 | High | 0.3% | 9.1 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.4… | |
| CVE-2026-2651 | High | 0.3% | 9.0 | A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart u… | |
| CVE-2026-67622 | High | 0.3% | 9.9 | Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the Op… | |
| CVE-2026-59151 | High | 0.3% | 9.6 | Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow … | |
| CVE-2025-9497 | High | 0.3% | 9.8 | Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicio… | |
| CVE-2026-39355 | High | 0.3% | 9.9 | Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access contr… | |
| CVE-2026-63296 | High | 0.3% | 9.9 | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass ta… | |
| CVE-2026-34361 | High | 0.3% | 9.3 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperab… | |
| CVE-2026-45372 | High | 0.3% | 9.9 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to… | |
| CVE-2026-78155 | High | 0.3% | 9.9 | privilege escalation in StackGres operator allows a low-privilege tenant who owns a databa… | |
| CVE-2026-12605 | High | 0.3% | 9.6 | In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSo… | |
| CVE-2026-78683 | High | 0.3% | 9.6 | NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization v… | |
| CVE-2026-32253 | High | 0.3% | 9.8 | Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.14… | |
| CVE-2026-33642 | High | 0.3% | 9.9 | Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_com… |