CVE search
401,239 resultsCVE-2026-103395CRITICALLightLLM through 1.2.0 Unauthenticated Remote Code Execution via Visual-Only RPyC ServiceEPSS 0.6%CVE-2026-103270HIGHLightLLM through 1.2.0 Missing Authentication on RL Control RoutesEPSS 0.5%CVE-2026-103243MEDIUMLightLLM through 1.2.0 Server-Side Request Forgery via multimodal endpointsEPSS 0.2%CVE-2026-76570CRITICALJoomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables < 1.21.1EPSS 0.5%CVE-2026-102984HIGHAstro: Malformed port in the Host header can crash the Node adapterEPSS 0.4%CVE-2026-102983MEDIUMAstro: Netlify Image CDN allowlist bypass enables SSRFEPSS 0.3%CVE-2026-102717HIGHMQTT WebSocket setter ABI mismatch may disclose memory or cause a crashEPSS 0.3%CVE-2026-47097HIGHAJA HELO Plus < 2.1.7 Hardcoded AES Passphrase for Diagnostics Export BundleEPSS 0.4%CVE-2026-103227MEDIUMGPAC DASH Client dash_client.c gf_dash_resolve_url buffer overflowEPSS 0.5%CVE-2026-103389MEDIUMMISP Stored Cross-Site Scripting via Unvalidated Galaxy Icon Field in Correlation GraphEPSS 0.3%CVE-2026-103388MEDIUMMISP Stored Cross-Site Scripting via JavaScript URL in Galaxy Cluster Source FieldEPSS 0.2%CVE-2026-18782CRITICALSQL Injection in Trex Digital Manufacturing's Trex MESEPSS 0.5%CVE-2026-103226MEDIUMArtifex Ghostscript Pdfwrite gdevpsfx.c type1_callsubr stack-based overflowEPSS 0.4%CVE-2026-18783HIGHMissing Server-Side Authentication on REST API Endpoint in Trex Digital Manufacturing's Trex MESEPSS 0.4%CVE-2026-97259MEDIUMWordPress Pay with Vipps for WooCommerce plugin <= 6.2.4 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.2%CVE-2026-101295HIGHOc-mirror: oc-mirror: path traversal / arbitrary file write in operator catalog image extractionEPSS 0.1%CVE-2026-62084MEDIUMWordPress User Submitted Posts plugin <= 20260810 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.1%CVE-2026-62097HIGHWordPress Business Directory plugin <= 6.4.27 - SQL Injection vulnerabilityEPSS 0.2%CVE-2026-103222MEDIUMBlosc C-Blosc2 blosclz Decompression blosclz.c blosclz_decompress integer overflowEPSS 0.3%CVE-2026-93903CRITICALLiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case."EPSS 0.3%