HALL OF FAME · PUBLIC RECORD
Proof, notpromises.
Every CVE BugBunny has discovered—public metadata, severity, score, and disclosure status in one record.
DISCOVERED CVEs
1100189
Public records
0221
Reserved disclosures
0350
High / critical
0410.0
Peak CVSS
THE COMPLETE RECORD · 110
Every CVE. One table.
Search by product or weakness, filter public and reserved work, and open the underlying advisory where available.
THE COMPLETE RECORD110 / 110
| No. | CVE | Product / issue | Severity | Score | Published | Record |
|---|---|---|---|---|---|---|
| 01 | CVE-2026-77537 | UniFi Protect ApplicationUnauthenticated Host Command Injection | Critical | 10.0/10 | August 26, 2026 | Public |
| 02 | CVE-2026-77536 | UniFi OSImproper Access Control Privilege Escalation | Critical | 9.9/10 | August 26, 2026 | Public |
| 03 | CVE-2026-75605 | Reserved CVEDetails withheld pending disclosure | None | pending | August 19, 2026 | Reserved |
| 04 | CVE-2026-40006 | Apache IoTDBIoTDB AirGap Receiver Heap-Exhaustion DoS | None | pending | July 10, 2026 | Public |
| 05 | CVE-2026-40007 | Apache IoTDBIoTDB AirGap Receiver Recursive Stack-Overflow DoS | None | pending | July 10, 2026 | Public |
| 06 | CVE-2026-40009 | Apache IoTDBIoTDB Internal Auditor Privilege Escalation | None | pending | July 10, 2026 | Public |
| 07 | CVE-2026-40452 | Apache IoTDBIoTDB fastLastQuery Authorization Bypass | None | pending | July 10, 2026 | Public |
| 08 | CVE-2026-60077 | Reserved CVEDetails withheld pending disclosure | None | pending | July 9, 2026 | Reserved |
| 09 | CVE-2026-60076 | Reserved CVEDetails withheld pending disclosure | None | pending | July 9, 2026 | Reserved |
| 10 | CVE-2026-33264 | Apache AirflowApache Airflow DAG Deserialization RCE | Critical | 9.8/10 | July 7, 2026 | Public |
| 11 | CVE-2026-9103 | IBM Langflow OSSLangflow Unauthenticated Superuser Token Issuance | Critical | 9.8/10 | July 2, 2026 | Public |
| 12 | CVE-2026-56842 | UniFi Network ApplicationUniFi Network Application Persistent Authorization | High | 7.5/10 | July 2, 2026 | Public |
| 13 | CVE-2026-48978 | oras-gooras-go Bearer Realm Credential Exfiltration | Low | 2.1/10 | July 1, 2026 | Public |
| 14 | CVE-2026-49478 | FulcioFulcio OIDC Discovery Redirect SSRF | High | 8.7/10 | June 30, 2026 | Public |
| 15 | CVE-2026-44947 | RancherRancher Legacy PRTB Permission Cleanup Issue | Medium | 6.9/10 | June 30, 2026 | Public |
| 16 | CVE-2026-52809 | GogsGogs Password Reset Token Lifetime Issue | Medium | 6.8/10 | June 24, 2026 | Public |
| 17 | CVE-2026-52808 | GogsGogs Repository Settings Authorization Bypass | High | 7.1/10 | June 24, 2026 | Public |
| 18 | CVE-2026-47733 | Rocket.ChatRocket.Chat Markdown Image URL XSS | Medium | 4.4/10 | June 24, 2026 | Public |
| 19 | CVE-2026-53930 | NocoDBNocoDB Base Migration SSRF | Medium | 5.1/10 | June 17, 2026 | Public |
| 20 | CVE-2026-53929 | Reserved CVEDetails withheld pending disclosure | None | pending | June 12, 2026 | Reserved |
| 21 | CVE-2026-53928 | Reserved CVEDetails withheld pending disclosure | None | pending | June 12, 2026 | Reserved |
| 22 | CVE-2026-53926 | Reserved CVEDetails withheld pending disclosure | None | pending | June 12, 2026 | Reserved |
| 23 | CVE-2026-44705 | tmptmp Prefix/Postfix Path Traversal | High | 7.7/10 | June 11, 2026 | Public |
| 24 | CVE-2026-45726 | Sidero OmniOmni Imported Cluster CA Key Exposure | High | 7.6/10 | June 5, 2026 | Public |
| 25 | CVE-2026-45723 | Sidero OmniOmni Image Factory Path Traversal | Low | 2.7/10 | June 5, 2026 | Public |
| 26 | CVE-2026-45720 | Sidero OmniOmni SAML Session Token Race | High | 7.0/10 | June 5, 2026 | Public |
| 27 | CVE-2026-50285 | Reserved CVEDetails withheld pending disclosure | None | pending | June 4, 2026 | Reserved |
| 28 | CVE-2026-45090 | DalfoxDalfox Parameter Analysis Denial of Service | High | 7.5/10 | May 27, 2026 | Public |
| 29 | CVE-2026-46554 | NocoDBNocoDB Stale Auth Cache After API Token Deletion | Low | pending | May 21, 2026 | Public |
| 30 | CVE-2026-46553 | NocoDBNocoDB Attachment Size Limit Bypass | Low | pending | May 21, 2026 | Public |
| 31 | CVE-2026-44310 | gitsigngitsign Empty Certificate Verification Panic | Medium | 5.4/10 | May 15, 2026 | Public |
| 32 | CVE-2026-44309 | gitsigngitsign Git Object Signature Verification Bypass | Medium | 5.3/10 | May 15, 2026 | Public |
| 33 | CVE-2026-24899 | Fleet Device ManagementFleet Windows MDM Azure AD JWT Authentication Bypass | High | 8.2/10 | May 14, 2026 | Public |
| 34 | CVE-2026-22706 | StrapiStrapi Password Reset Session Persistence | Low | 2.1/10 | May 13, 2026 | Public |
| 35 | CVE-2026-45022 | go-gitgo-git Object Parsing Signature Confusion | High | 7.0/10 | May 11, 2026 | Public |
| 36 | CVE-2026-44247 | VolcanoVolcano Webhook Unbounded-Body DoS | Medium | 6.8/10 | May 8, 2026 | Public |
| 37 | CVE-2026-43888 | OutlineOutline Stored XSS | High | 8.7/10 | May 7, 2026 | Public |
| 38 | CVE-2026-43889 | OutlineOutline Access Control Issue | Medium | 6.5/10 | May 7, 2026 | Public |
| 39 | CVE-2026-43999 | vm2vm2 Sandbox Escape | Critical | 9.9/10 | May 5, 2026 | Public |
| 40 | CVE-2026-43998 | vm2vm2 Sandbox Boundary Bypass | High | 8.5/10 | May 5, 2026 | Public |
| 41 | CVE-2026-42883 | AudiobookshelfAudiobookshelf Access Control Issue | Medium | 6.5/10 | May 4, 2026 | Public |
| 42 | CVE-2026-42884 | AudiobookshelfAudiobookshelf Authorization Issue | Medium | 4.3/10 | May 4, 2026 | Public |
| 43 | CVE-2026-42885 | AudiobookshelfAudiobookshelf Authorization Issue | Medium | 4.3/10 | May 4, 2026 | Public |
| 44 | CVE-2026-42886 | AudiobookshelfAudiobookshelf Authorization Issue | Medium | 4.9/10 | May 4, 2026 | Public |
| 45 | CVE-2026-44442 | ERPNextERPNext Missing Authorization | Critical | 9.9/10 | April 30, 2026 | Public |
| 46 | CVE-2026-44446 | ERPNextERPNext SQL Injection | High | 8.8/10 | April 30, 2026 | Public |
| 47 | CVE-2026-42275 | zrokzrok WebDAV Symlink Escape | High | 8.7/10 | April 25, 2026 | Public |
| 48 | CVE-2026-41590 | Reserved CVEDetails withheld pending disclosure | High | 7.8/10 | April 22, 2026 | Reserved |
| 49 | CVE-2026-41131 | OpenFGAOpenFGA Authorization Issue | Medium | 5.0/10 | April 20, 2026 | Public |
| 50 | CVE-2026-40914 | Reserved CVEDetails withheld pending disclosure | None | pending | April 20, 2026 | Reserved |
| 51 | CVE-2026-40454 | Reserved CVEDetails withheld pending disclosure | None | pending | April 18, 2026 | Reserved |
| 52 | CVE-2026-40304 | zrokzrok Broken Ownership Check | Medium | 5.3/10 | April 16, 2026 | Public |
| 53 | CVE-2026-40302 | zrokzrok OAuth Callback Reflected XSS | Medium | 6.1/10 | April 16, 2026 | Public |
| 54 | CVE-2026-40293 | OpenFGAOpenFGA Authorization Issue | Medium | 6.5/10 | April 10, 2026 | Public |
| 55 | CVE-2026-40165 | Reserved CVEDetails withheld pending disclosure | High | 8.7/10 | April 10, 2026 | Reserved |
| 56 | CVE-2026-35441 | DirectusDirectus Security Boundary Issue | High | 7.5/10 | April 7, 2026 | Public |
| 57 | CVE-2026-34972 | OpenFGAOpenFGA Authorization Model Disclosure | Medium | 5.0/10 | April 6, 2026 | Public |
| 58 | CVE-2026-35214 | BudibaseBudibase Plugin Upload Path Traversal | High | 8.7/10 | April 4, 2026 | Public |
| 59 | CVE-2026-35413 | DirectusDirectus Security Boundary Issue | Medium | 5.3/10 | April 2, 2026 | Public |
| 60 | CVE-2026-35412 | DirectusDirectus Security Boundary Issue | High | 7.1/10 | April 2, 2026 | Public |
| 61 | CVE-2026-4800 | lodashlodash Template Code Injection | High | 8.1/10 | April 1, 2026 | Public |
| 62 | CVE-2026-34750 | PayloadPayload Client Upload Filename Validation | Medium | 6.5/10 | April 1, 2026 | Public |
| 63 | CVE-2026-34749 | PayloadPayload Authentication CSRF Bypass | Medium | 5.4/10 | April 1, 2026 | Public |
| 64 | CVE-2026-34748 | PayloadPayload Admin Stored XSS | High | 8.7/10 | April 1, 2026 | Public |
| 65 | CVE-2026-34746 | PayloadPayload Upload SSRF | High | 7.7/10 | April 1, 2026 | Public |
| 66 | CVE-2026-34595 | Parse ServerParse Server Authorization Issue | Medium | 4.3/10 | March 28, 2026 | Public |
| 67 | CVE-2026-34574 | Parse ServerParse Server Authorization Issue | Medium | 5.4/10 | March 28, 2026 | Public |
| 68 | CVE-2026-34573 | Parse ServerParse Server Security Boundary Issue | High | 7.5/10 | March 28, 2026 | Public |
| 69 | CVE-2026-34532 | Parse ServerParse Server Critical Authorization Issue | Critical | 9.1/10 | March 28, 2026 | Public |
| 70 | CVE-2026-34198 | Reserved CVEDetails withheld pending disclosure | Medium | 5.3/10 | March 26, 2026 | Reserved |
| 71 | CVE-2026-34171 | Reserved CVEDetails withheld pending disclosure | High | 8.0/10 | March 26, 2026 | Reserved |
| 72 | CVE-2026-34170 | Reserved CVEDetails withheld pending disclosure | Medium | 4.3/10 | March 26, 2026 | Reserved |
| 73 | CVE-2026-34167 | Reserved CVEDetails withheld pending disclosure | Medium | 5.0/10 | March 26, 2026 | Reserved |
| 74 | CVE-2026-34158 | Reserved CVEDetails withheld pending disclosure | High | 8.8/10 | March 26, 2026 | Reserved |
| 75 | CVE-2026-34037 | Reserved CVEDetails withheld pending disclosure | None | pending | March 24, 2026 | Reserved |
| 76 | CVE-2026-33413 | etcdetcd Authorization Bypass Across Multiple APIs | High | 8.8/10 | March 20, 2026 | Public |
| 77 | CVE-2026-33016 | Reserved CVEDetails withheld pending disclosure | High | 8.8/10 | March 2026 | Reserved |
| 78 | CVE-2026-33037 | AVideoAVideo Default Admin Credential | High | 8.1/10 | March 2026 | Public |
| 79 | CVE-2026-33038 | AVideoAVideo Installer Takeover | High | 8.1/10 | March 2026 | Public |
| 80 | CVE-2026-33039 | AVideoAVideo LiveLinks Redirect SSRF | High | 8.6/10 | March 2026 | Public |
| 81 | CVE-2026-31888 | ShopwareShopware Store API User Enumeration | Medium | 5.3/10 | March 11, 2026 | Public |
| 82 | CVE-2026-30973 | @appium/supportAppium Zip Slip Arbitrary File Write | Medium | 6.5/10 | March 9, 2026 | Public |
| 83 | CVE-2026-24015 | Apache IoTDBApache IoTDB Insecure Default Network Binding | None | pending | March 9, 2026 | Public |
| 84 | CVE-2026-29093 | AVideoAVideo Exposed Memcached Session Store | High | 8.1/10 | March 2026 | Public |
| 85 | CVE-2026-28398 | NocoDBNocoDB Stored XSS via Comments and Rich Text | Medium | 5.3/10 | March 2026 | Public |
| 86 | CVE-2026-28396 | NocoDBNocoDB Refresh Tokens Survive Password Reset | Medium | 4.9/10 | March 2026 | Public |
| 87 | CVE-2026-28361 | NocoDBNocoDB MCP Token Ownership Bypass | Medium | 4.9/10 | March 2026 | Public |
| 88 | CVE-2026-3351 | LXDLXD Certificate Fingerprint Enumeration | Medium | 4.3/10 | March 2026 | Public |
| 89 | CVE-2026-28445 | Reserved CVEDetails withheld pending disclosure | High | 8.7/10 | February 2026 | Reserved |
| 90 | CVE-2026-28351 | pypdfpypdf RunLengthDecode Memory Exhaustion | Medium | 6.9/10 | February 2026 | Public |
| 91 | CVE-2026-28217 | HoppscotchHoppscotch userCollection IDOR | Medium | 6.5/10 | February 2026 | Public |
| 92 | CVE-2026-28215 | HoppscotchHoppscotch Infrastructure Configuration Overwrite | Critical | 9.1/10 | February 24, 2026 | Public |
| 93 | CVE-2026-28444 | Reserved CVEDetails withheld pending disclosure | Medium | 6.5/10 | February 2026 | Reserved |
| 94 | CVE-2026-28384 | LXDLXD compression_algorithm Host RCE | Critical | 9.9/10 | February 2026 | Public |
| 95 | CVE-2026-27955 | Reserved CVEDetails withheld pending disclosure | Medium | 6.6/10 | February 2026 | Reserved |
| 96 | CVE-2026-27806 | Fleet OrbitFleet Orbit Tcl Injection Privilege Escalation | High | 7.8/10 | February 2026 | Public |
| 97 | CVE-2026-27471 | ERPNextERPNext Missing Access Validation | Critical | 9.1/10 | February 2026 | Public |
| 98 | CVE-2026-23630 | DocmostDocmost Mermaid XSS | Medium | 5.4/10 | January 2026 | Public |
| 99 | CVE-2026-22807 | vLLMvLLM auto_map RCE | High | 8.8/10 | January 12, 2026 | Public |
| 100 | CVE-2026-21884 | React RouterReact Router ScrollRestoration XSS | High | 8.2/10 | January 12, 2026 | Public |
| 101 | CVE-2025-64756 | glob CLIglob CLI Command Injection | High | 7.5/10 | November 2025 | Public |
| 102 | CVE-2025-62232 | Apache APISIXApache APISIX Basic-Auth Credential Logging | None | pending | October 31, 2025 | Public |
| 103 | CVE-2025-62228 | Apache Flink CDCApache Flink CDC Identifier SQL Injection | Medium | 5.1/10 | October 9, 2025 | Public |
| 104 | CVE-2025-61686 | React RouterReact Router Path Traversal | Critical | 9.1/10 | October 2025 | Public |
| 105 | CVE-2025-59343 | tar-fstar-fs Symlink Validation Bypass | High | 8.7/10 | September 24, 2025 | Public |
| 106 | CVE-2025-61622 | Apache ForyApache Fory Pickle RCE | Critical | 9.8/10 | September 2025 | Public |
| 107 | CVE-2025-59792 | Apache KvrocksApache Kvrocks Credential Exposure | Medium | 5.3/10 | August 2025 | Public |
| 108 | CVE-2025-59790 | Apache KvrocksApache Kvrocks Privilege Escalation | Medium | 5.4/10 | August 2025 | Public |
| 109 | CVE-2025-59057 | React RouterReact Router Stored XSS | High | 7.6/10 | July 2025 | Public |
| 110 | CVE-2025-58434 | FlowiseFlowise Account Takeover | Critical | 9.8/10 | June 2025 | Public |
ABOUT RESERVED RECORDS
Reserved entries are real assigned CVEs. Product and technical details remain withheld until coordinated disclosure is complete.
Disclosure policyPUT THE RECORD TO WORK