CVE search

398,693 results
CVE-2026-101057LOWutcp-mcp before 1.1.3 SSRF via unvalidated MCP server URLEPSS —CVE-2026-101056MEDIUMCloudreve before 4.16.1 Authentication Bypass via Cached Context HintEPSS —CVE-2026-101051LOWCloudreve before 4.16.1 Path Traversal via Remote DownloadEPSS —CVE-2026-101048MEDIUMCloudreve before 4.17.0 SSRF via Admin.Read OAuth scopeEPSS —CVE-2026-101047MEDIUMFleet before 4.87.0 Unauthenticated iOS App Download via Predictable URLsEPSS —CVE-2026-101046LOWFleet before 4.89.0 SQL Injection via ORDER BY Activity EndpointsEPSS —CVE-2026-101045HIGHFleet Homebrew Cask OS Command Injection via MetadataEPSS —CVE-2026-101044HIGHpacquet before 12.0.0-alpha.5 Path Traversal via lockfile aliasEPSS —CVE-2026-101043HIGHpnpm 11.0.0 before 11.11.0 Environment Variable Exfiltration via Proxy SettingsEPSS —CVE-2026-88778HIGHTCP Initial Sequence Number (ISN) predictionEPSS —CVE-2026-88777HIGHMemory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of ServiceEPSS —CVE-2026-88776HIGHMemory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of ServiceEPSS —CVE-2026-101050HIGHHeym before 0.0.53 Authentication Bypass via Telegram WebhookEPSS —CVE-2026-101049HIGHHeym before 0.0.53 Slack Webhook Signature Verification BypassEPSS —CVE-2026-101042HIGHParse Server 9.0.0 Authentication Bypass via Unverified Provider IdentityEPSS —CVE-2026-88775HIGHMemory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of ServiceEPSS —CVE-2026-88773CRITICALHTTP Request SmugglingEPSS —CVE-2026-88774HIGHFeature policy bypass due to improper HTTP URL based expression usageEPSS —CVE-2026-88772CRITICALMemory overflow vulnerability leading to Remote Code Execution or Denial of ServiceEPSS —KEVCVE-2026-88771CRITICALA remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commandsEPSS —KEV