CVE search

401,083 results
CVE-2026-103474HIGHyii2-starter-kit through 4.2.0 Unrestricted File Upload RCEEPSS 0.4%CVE-2026-103473CRITICALDeno 2.7.0 through 2.9.7 Command Injection via node:child_processEPSS 1.5%CVE-2026-103472HIGHrestbed through 5.0.0 WebSocket Memory Exhaustion via Unbounded Frame BufferingEPSS 0.4%CVE-2026-103471HIGHrestbed through 5.0.0 Denial of Service via Unbounded Header BufferingEPSS 0.6%CVE-2026-103437LOWReadingLists imported metadata permits JavaScript URL XSSEPSS 0.3%CVE-2026-103500—Heap buffer overflow opening large emailEPSS 0.2%CVE-2026-103446HIGHWikiLambda exposes anonymous execution of unsaved Abstract Wikipedia fragmentsEPSS 0.3%CVE-2026-53605HIGHReachy Mini Wireless: Local Privilege Escalation via Unrestricted sudo systemctl GrantEPSS 0.1%CVE-2026-55107CRITICALKobako Vulnerable to Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)EPSS 0.8%CVE-2026-103445LOWStored XSS through PageForms #autoedit redirect linksEPSS 0.3%CVE-2026-87004HIGHTugtainer: OIDC id_token claims accepted without signature/audience/expiry verificationEPSS 0.3%CVE-2026-62308CRITICALTugtainer: Authenticated SSRF via arbitrary notification URLs in test_notification endpointEPSS 0.3%CVE-2026-55494CRITICALTugtainer: Unauthenticated access to Tugtainer Agent Docker management APIs when AGENT_SECRET is unsetEPSS 0.6%CVE-2026-55181CRITICALTugtainer: OIDC login remains accessible when OIDC_ENABLED is falseEPSS 0.6%CVE-2026-103241MEDIUMvllm-project vLLM Gemma4UnifiedParser gemma4.rs denial of serviceEPSS 0.7%CVE-2026-55176CRITICALSoft Machine: Cross-tenant workspace API auth bypass via shared `CONTAINER_SHARED_SECRET` bearer tokenEPSS 0.2%CVE-2026-103233MEDIUMAdithyaYelloju Restaurant-Management-System Admin Area admin authorizationEPSS 0.4%CVE-2026-46711HIGHSoft Machine: Unauthenticated workspace API exposes arbitrary file read & directory exfiltration to any peer on the Fly private networkEPSS 0.3%CVE-2026-75969CRITICALPTZOptics Missing Authentication in Firmware UploadEPSS 0.4%CVE-2026-55177HIGHCloudTAK: Authenticated full-read SSRF in /api/esri* routes — user-controlled URL fetched with no IP-classification guardEPSS 0.4%