Filter and search through 392,315 vulnerabilities
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-23880 | OnboardLite is a comprehensive membership lifecycle platform built for student organizations at the University of Central Florida. Versions of the sof... | 7.3 | 343 | Neutral | No |
| No |
| CVE-2026-23878 | HotCRP is conference review software. Starting in commit aa20ef288828b04550950cf67c831af8a525f508 and prior to commit ceacd5f1476458792c44c6a993670f02... | 6.5 | 217 | Neutral | No | No |
| CVE-2026-23877 | ### Summary Swing Music's `list_folders()` function in the `/folder/dir-browser` endpoint is vulnerable to directory traversal attacks. Any authentica... | 0.0 | 0 | Neutral | No | Yes |
| CVE-2026-23876 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer... | 8.1 | 482 | Neutral | No | Yes |
| CVE-2026-23875 | CrawlChat is an open-source, AI-powered platform that transforms technical documentation into intelligent chatbots. Prior to version 0.0.8, a non-exis... | 0.0 | 0 | Neutral | No | No |
| CVE-2026-23874 | ## Summary Stack overflow via infinite recursion in MSL (Magick Scripting Language) `<write>` command when writing to MSL format. ## Version - Imag... | 5.5 | 125 | Neutral | No | Yes |
| CVE-2026-23873 | hustoj is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. All versions are vulnerable to CSV Injection (Formu... | 0.0 | 0 | Neutral | No | No |
| CVE-2026-23864 | Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-d... | 7.5 | 394 | Neutral | No | No |
| CVE-2026-23852 | SiYuan is a personal knowledge management system. Versions prior to 3.5.4 have a stored Cross-Site Scripting (XSS) vulnerability that allows an attack... | 0.0 | 0 | Neutral | No | No |
| CVE-2026-23851 | ### Summary The SiYuan Note application (v3.5.3) contains a logic vulnerability in the /api/file/globalCopyFiles endpoint. The function allows authent... | 0.0 | 0 | Neutral | No | Yes |
| CVE-2026-23850 | ### Summary Markdown feature allows unrestricted server side html-rendering which allows arbitary file read (LFD) and fully SSRF access We in @0xL4ugh... | 0.0 | 0 | Neutral | No | Yes |
| CVE-2026-23849 | ### Summary The JSONAuth.Auth function contains a logic flaw that allows unauthenticated attackers to enumerate valid usernames by measuring the respo... | 5.3 | 124 | Neutral | No | Yes |
| CVE-2026-23848 | MyTube is a self-hosted downloader and player for several video websites. Prior to version 1.7.71, a rate limiting bypass via `X-Forwarded-For` header... | 6.5 | 224 | Neutral | No | No |
| CVE-2026-23847 | ### Summary Reflected XSS in /api/icon/getDynamicIcon due to unsanitized SVG input. ### Details The endpoint generates SVG images for text icons (type... | 0.0 | 0 | Neutral | No | Yes |
| CVE-2026-23846 | Tugtainer is a self-hosted app for automating updates of Docker containers. In versions prior to 1.16.1, the password authentication mechanism transmi... | 8.1 | 484 | Neutral | No | No |
| CVE-2026-23845 | ### Server-Side Request Forgery (SSRF) via HTML Check CSS Download The HTML Check feature (`/api/v1/message/{ID}/html-check`) is designed to analyze ... | 5.8 | 277 | Neutral | No | Yes |
| CVE-2026-23844 | Whisper Money is a personal finance application. Versions prior to 0.1.5 have an insecure direct object reference vulnerability. A user can update/cre... | 0.0 | 0 | Neutral | No | No |
| CVE-2026-23843 | teklifolustur_app is a web-based PHP application that allows users to create, manage, and track quotes for their clients. Prior to commit dd082a134a22... | 7.1 | 313 | Neutral | No | No |
| CVE-2026-23842 | ### Summary ChatterBot versions up to 1.2.10 are vulnerable to a denial-of-service condition caused by improper database session and connection pool m... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-23841 | Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-sit... | 9.3 | 577 | Neutral | No | No |