CVE search
369,562 resultsCVE-2026-58578HIGHLobeChat < 2.2.10-canary.15 - Regular Expression Denial of Service in GitHub Skill ImportEPSS 0.3%CVE-2025-71385MEDIUMNetdata < 2.3.1 - Reflected Cross-Site Scripting via love Parameter in ilove.svg EndpointEPSS 0.2%CVE-2026-13743LOWImproper verification of cryptographic signature in CubeSpace CW0057 Reaction WheelEPSS 0.1%CVE-2026-7311HIGHTinyPNG <= 3.6.13 - Authenticated (Author+) Arbitrary File Deletion via 'convert.path' in 'tiny_compress_images' Post MetaEPSS 0.7%CVE-2026-58465HIGHEclipse Wakaama CoAP Block1 Handler Unbounded Memory Allocation DoSEPSS 0.6%CVE-2024-58352HIGHLandray OA Unauthenticated HQL Injection via wechatLoginHelper.doEPSS 0.6%CVE-2022-50973CRITICALYonyou KSOA 9.0 Unauthenticated File Upload RCE via ImageUpload ServletEPSS 0.9%CVE-2024-14037CRITICALRedsea Cloud eHR Unauthenticated File Upload RCE via PtFjk.mobEPSS 0.7%CVE-2026-8699HIGHStored Cross-Site Scripting (XSS) in TP-Link Archer C5 Web Management InterfaceEPSS 0.2%CVE-2026-50282MEDIUMCraft CMS: Unauthorized Deletion of Destination Folders During Forced MovesEPSS 0.2%CVE-2026-54891MEDIUMPlaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in sslEPSS 0.1%CVE-2026-55950HIGHDTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessionsEPSS 0.4%CVE-2026-54886MEDIUMSSH SFTP server denial of service via extended channel data infinite loopEPSS 0.3%CVE-2026-55952HIGHTLS 1.3 server denial of service via malformed ClientHello pre-shared key extensionEPSS 0.5%CVE-2026-54887MEDIUMDTLS server cookie bypass during startup window due to empty initial cookie secretEPSS 0.2%CVE-2026-53422LOWSFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured rootEPSS 0.3%CVE-2026-50281HIGHCraft CMS: Mass assignment via id in newAttributes during bulk duplicate overwrites existing elementsEPSS 0.3%CVE-2026-44935CRITICALRancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm DeployerEPSS 0.6%CVE-2026-44941HIGHlibzypp path traversal via "keyhint" in repomd.xmlEPSS 0.5%CVE-2026-58455CRITICALDockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.phpEPSS 1.2%