CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-55252 MEDIUM

OpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect

CVSS 5.1 EPSS n/a Oct 1, 2026
Go
CVE-2026-63209 HIGH

Integer Overflow or Wraparound and Out-of-bounds Write in compress

CVSS 7.5 EPSS 0.36% Sep 29, 2026
Go
CVE-2026-101090 CRITICAL

Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri

CVSS 9.3 EPSS 0.36% Sep 27, 2026
Go
CVE-2026-101084 CRITICAL

obot before v0.21.1 Authorization Bypass via /mcp-connect

CVSS 9.3 EPSS 0.28% Sep 27, 2026
Go
CVE-2026-101064 HIGH

Obot before v0.23.0 Server-Side Request Forgery via MCP

CVSS 8.3 EPSS 0.24% Sep 27, 2026
Go
CVE-2026-101063 MEDIUM

Obot before v0.23.0 Authentication Bypass via Registry API

CVSS 6.9 EPSS 0.24% Sep 27, 2026
Go
CVE-2026-101062 HIGH

Obot before v0.23.0 Authentication Bypass via OAuth Dynamic Client Registration

CVSS 8.7 EPSS 0.34% Sep 27, 2026
Go
CVE-2026-101056 MEDIUM

Cloudreve before 4.16.1 Authentication Bypass via Cached Context Hint

CVSS 6.9 EPSS 0.19% Sep 27, 2026
Go
CVE-2026-101051 LOW

Cloudreve before 4.16.1 Path Traversal via Remote Download

CVSS 2.3 EPSS 0.22% Sep 27, 2026
Go
CVE-2026-101048 MEDIUM

Cloudreve before 4.17.0 SSRF via Admin.Read OAuth scope

CVSS 5.3 EPSS 0.19% Sep 27, 2026
Go
CVE-2026-101047 MEDIUM

Fleet before 4.87.0 Unauthenticated iOS App Download via Predictable URLs

CVSS 6.9 EPSS 0.24% Sep 27, 2026
Go
CVE-2026-101046 LOW

Fleet before 4.89.0 SQL Injection via ORDER BY Activity Endpoints

CVSS 2.3 EPSS 0.17% Sep 27, 2026
Go
CVE-2026-100837 MEDIUM

Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching

CVSS 6.3 EPSS 0.21% Sep 27, 2026
Go
CVE-2026-100836 MEDIUM

Edgeless Systems Contrast through 1.20.0 Denial of Service via ciphertextContainer

CVSS 5.3 EPSS 0.15% Sep 27, 2026
Go
CVE-2026-100839 HIGH

Contrast before 1.18.0 AML Injection Remote Code Execution

CVSS 8.4 EPSS 0.15% Sep 27, 2026
Go
CVE-2026-100838 HIGH

Contrast before 1.19.1 CopyFile Policy Symlink Subversion

CVSS 8.6 EPSS 0.22% Sep 27, 2026
Go
CVE-2025-71426 HIGH

Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery

CVSS 7.1 EPSS 0.14% Sep 27, 2026
Go
CVE-2025-71425 HIGH

Contrast before 1.8.1 Information Disclosure via Logging

CVSS 8.5 EPSS 0.19% Sep 27, 2026
Go
CVE-2025-71424 MEDIUM

Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount

CVSS 5.1 EPSS 0.16% Sep 27, 2026
Go
CVE-2025-71423 HIGH

Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure

CVSS 8.5 EPSS 0.21% Sep 27, 2026
Go
CVE-2025-71422 MEDIUM

Contrast before 1.12.1 Insecure LUKS2 Persistent Storage

CVSS 6.9 EPSS 0.07% Sep 27, 2026
Go
CVE-2026-53493 MEDIUM

Containerd has image-pull DoS via crafted OCI index graph amplification

CVSS 6.9 EPSS 0.36% Sep 25, 2026
Go
CVE-2026-62286 MEDIUM

Dozzle label filters do not restrict container event and statistics streams

CVSS 4.3 EPSS 0.34% Sep 24, 2026
Go
CVE-2026-61604 CRITICAL

ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass

CVSS 9.3 EPSS 0.27% Sep 24, 2026
Go
CVE-2026-85056 HIGH

ZITADEL: MFA bypass via session reuse in Login V2

CVSS 8.2 EPSS 0.29% Sep 24, 2026
Go

Showing 1 to 25 CVEs · page 1 (more available)