CVE search

369,464 results
CVE-2026-20909MEDIUMGitea tracked-time list endpoint has insufficient permission checksEPSS 0.3%CVE-2026-20896CRITICALGitea Docker image trusts spoofable reverse-proxy headers by defaultEPSS 0.8%CVE-2026-20779HIGHGitea TOTP single-use enforcement defect allows OTP replayEPSS 0.5%CVE-2026-20706CRITICALGitea repository archive downloads bypass token scope checksEPSS 0.4%CVE-2026-14609MEDIUMSourceCodester CET Automated Grading System with AI Predictive Analytics session fixiationEPSS 0.3%CVE-2026-14608MEDIUMSourceCodester CET Automated Grading System with AI Predictive Analytics POST index.php view_student authorizationEPSS 0.2%CVE-2026-14607MEDIUMRT-Thread lwp_syscall.c sys_getaddrinfo memory corruptionEPSS 0.1%CVE-2026-14606HIGHRT-Thread SWM341 CAN SWM341.h CAN_Receive stack-based overflowEPSS 0.1%CVE-2026-14605HIGHRT-Thread ls1c CAN ls1c_can.h recvmsg stack-based overflowEPSS 0.1%CVE-2026-14604MEDIUMOpen Asset Import Library Assimp PLY Model PlyLoader.cpp ExportToBlob double freeEPSS 0.2%CVE-2026-58379HIGHGimp: gimp: heap buffer overflow in read_channel_data()EPSS 0.2%CVE-2026-14631MEDIUMwebpack-dev-server vulnerable to denial of service via a malformed Host or Origin headerEPSS 0.3%CVE-2026-14620MEDIUMwebpack-dev-server vulnerable to cross-site request forgery via internal developer endpointsEPSS 0.1%CVE-2026-14615MEDIUMKeycloak-services: keycloak: fgap v2 parent group children endpoint bypasses per-child view permission filterEPSS 0.2%CVE-2026-14614MEDIUMKeycloak-services: keycloak-services: fgap v2 client scope assignment bypass via clientresourceEPSS 0.1%CVE-2026-14613MEDIUMKeycloak-services: keycloak-services: keycloak: fgap v2 role groups endpoint discloses hidden group metadata without group view permissionEPSS 0.2%CVE-2026-14612MEDIUMFreeipa: ipa: idm: freeipa: off-by-one buffer overflows in ipa-otpd oauth2.c during oauth2 device authorizationEPSS 0.1%CVE-2026-49813MEDIUMDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 0.5%CVE-2026-14460HIGHMissing Authorization in TUBITAK BILGEM's pardus-softwareEPSS 0.2%CVE-2026-49814HIGHDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 1.2%