CVE Vulnerability Database

Search and browse 389,962 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-15747CRITICAL9.1Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH...
CVE-2026-15715MEDIUM4.3A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability i...
CVE-2026-0515MEDIUM6.2Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a cra...
CVE-2026-59891CRITICAL9.6sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials...
CVE-2026-59888MEDIUM6.5jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From...
CVE-2026-59886HIGH7.5pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and expon...
CVE-2026-59885HIGH7.5pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER a...
CVE-2026-59884HIGH7.5pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses lo...
CVE-2026-59200HIGH7.5Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib...
CVE-2026-59197HIGH8.2Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bo...
CVE-2026-58647MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized at...
CVE-2026-58644CRITICAL9.8Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a ...
CVE-2026-58640HIGH7.8Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-58636HIGH7.8Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to ele...
CVE-2026-58635HIGH7.8Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows a...
CVE-2026-58631HIGH7.8Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
CVE-2026-58618HIGH7.8Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-58614MEDIUM5.5Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.
CVE-2026-58610HIGH7.8Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally...
CVE-2026-58609HIGH7.8Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.
CVE-2026-58608HIGH7.5Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Com...
CVE-2026-58602HIGH7.8Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-58601HIGH7.8Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privilege...
CVE-2026-58595HIGH8.1Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to pe...
CVE-2026-58526HIGH7.8Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.