CVE search

370,413 results
CVE-2026-54260MEDIUMWagtail: Denial of service via unbounded filter specs in the image previewEPSS 0.2%CVE-2026-14340MEDIUMAn incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositoriesEPSS 0.2%CVE-2026-54720MEDIUMSilverstripe Framework: Possible XSS attack through media embedEPSS 0.2%CVE-2026-55660HIGHTinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeoverEPSS 0.2%CVE-2026-54074HIGH@tinacms/cli: Remote Code Execution via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labelsEPSS 0.2%CVE-2026-55661MEDIUMTinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemesEPSS 0.2%CVE-2026-58263HIGHJodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrierEPSS 0.2%CVE-2026-54756MEDIUMJodit Editor: Prototype pollution via Jodit.configure() / ConfigMergeEPSS 0.3%CVE-2026-55886MEDIUMJodit Editor: Prototype Pollution in Jodit via Jodit.modules.Helpers.set()EPSS 0.3%CVE-2026-50521HIGHMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-54786LOWWasmtime: Leak in WASIp1 `fd_renumber` implementationEPSS 0.2%CVE-2026-55153HIGHmchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"EPSS 0.3%CVE-2026-55688MEDIUMAsyncHttpClient: Cookie stored for an unrelated domain (cookie tossing) via ThreadSafeCookieStoreEPSS 0.2%CVE-2026-54908MEDIUMPion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange messageEPSS 0.3%CVE-2026-14265HIGHRCE via Deserialization in AWS Advanced JDBC WrapperEPSS 0.4%CVE-2026-58593HIGHNodeBB - ActivityPub Author Spoofing via Unvalidated attributedTo Mapped to Local UserEPSS 0.2%CVE-2026-58592HIGHLadybird - Web-Reachable Code Execution via Dangling FunctionType Reference in WebAssembly ESM IntegrationEPSS 0.3%CVE-2026-49858MEDIUMAPI Platform Core: Cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gateEPSS 0.2%CVE-2026-58457CRITICALShenzhen Aitemi M300 MT02 Unauthenticated OS Command Injection via protocol.cspEPSS 1.7%CVE-2026-14363MEDIUMCargo Extension: SQLi in Special:DrilldownEPSS 0.3%