CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-55178 HIGH

GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data

CVSS 7.5 EPSS 0.65% Sep 15, 2026
PyPInpm
CVE-2026-43871 HIGH

Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit

CVSS 8.7 EPSS 1.03% Jul 27, 2026
GoMavenPackagistPyPI
CVE-2026-47144 MEDIUM

Shamefile has an arbitrary file read via shamefile.yaml in shame next

CVSS 5.5 EPSS 0.18% Jul 20, 2026
PyPIcrates.ionpm
CVE-2026-53598 HIGH

Prompty: Arbitrary File Read via ${file:path} Reference Expansion

CVSS 7.5 EPSS 1.29% Jul 16, 2026
NuGetPyPIcrates.ionpm
CVE-2026-54527 CRITICAL

JupyterLab Git: Stored XSS leading to RCE

CVSS 9.3 EPSS 0.53% Jul 8, 2026
PyPInpm
CVE-2026-48797 CRITICAL

Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication

CVSS 9.3 EPSS 0.57% Jun 16, 2026
PyPInpm
CVE-2026-46695 CRITICAL

BoxLite: Permission Bypass in boxlite Allows Modification of Read-Only Files

CVSS 10.0 EPSS 0.48% Jun 10, 2026
GoPyPIcrates.ionpm
CVE-2026-46703 CRITICAL

BoxLite: Path Traversal Vulnerability in boxlite Leads to Arbitrary File Write on the Host

CVSS 9.6 EPSS 0.78% Jun 10, 2026
GoPyPIcrates.ionpm
CVE-2026-45134 HIGH

LangSmith Client SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning

CVSS 7.1 EPSS 0.34% May 27, 2026
PyPInpm
CVE-2026-44721 HIGH

Open WebUI: Stored XSS via Model Description

CVSS 7.3 EPSS 0.37% May 15, 2026
PyPInpm
CVE-2026-44503 HIGH

Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect

CVSS 7.0 EPSS 0.84% May 14, 2026
GoMavenNuGetPyPInpm
CVE-2025-65719 CRITICAL

An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted HTML page.

CVSS 9.8 EPSS 0.58% May 12, 2026
PyPInpm
CVE-2026-40171 HIGH

Jupyter Notebook and JupyterLab token theft via stored XSS in help command linker

CVSS 8.4 EPSS 0.66% May 6, 2026
PyPInpm
CVE-2026-41182 MEDIUM

LangSmith SDK: Streaming token events bypass output redaction

CVSS 5.3 EPSS 0.36% Apr 23, 2026
PyPInpm
CVE-2026-26118 HIGH

Azure MCP Server Tools Elevation of Privilege Vulnerability

CVSS 8.8 EPSS 0.86% Mar 10, 2026
NuGetPyPInpm
CVE-2026-25528 MEDIUM

LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection

CVSS 5.8 EPSS 0.33% Feb 9, 2026
PyPInpm
CVE-2026-22696 CRITICAL

dcap-qvl has Missing Verification for QE Identity

CVSS 9.3 EPSS 0.21% Jan 26, 2026
PyPIcrates.ionpm
CVE-2025-68113 MEDIUM

ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay

CVSS 6.5 EPSS 0.46% Dec 16, 2025
GoHexMavenPackagistPyPIRubyGemsnpm
CVE-2025-64496 HIGH

Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events

CVSS 8.0 EPSS 7.77% Nov 8, 2025
PyPInpm
CVE-2025-64495 HIGH

Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE

CVSS 8.7 EPSS 0.46% Nov 8, 2025
PyPInpm
CVE-2025-11849 MEDIUM

Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth b…

CVSS 6.4 EPSS 1.01% Oct 17, 2025
MavenNuGetPyPInpm
CVE-2024-12537 HIGH

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

CVSS 7.5 EPSS 0.84% Mar 20, 2025
PyPInpm
CVE-2024-12534 HIGH

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

CVSS 7.5 EPSS 0.78% Mar 20, 2025
PyPInpm
CVE-2024-47529 MEDIUM

OpenC3 COSMOS uses clear text storage of password/token (`GHSL-2024-129`)

CVSS 5.9 EPSS 0.35% Oct 2, 2024
PyPIRubyGemsnpm
CVE-2024-43795 MEDIUM

OpenC3 COSMOS vulnerable to cross-site scripting in Login functionality (`GHSL-2024-128`)

CVSS 5.1 EPSS 0.48% Oct 2, 2024
PyPIRubyGemsnpm

Showing 1 to 25 CVEs · page 1 (more available)