CVE Vulnerability Database

Search and browse 376,466 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-68091In the Linux kernel, the following vulnerability has been resolved: HID: wacom: stop hardware after post-start probe fa...
CVE-2026-68090In the Linux kernel, the following vulnerability has been resolved: debugobjects: Plug race against a concurrent OOM di...
CVE-2026-68089In the Linux kernel, the following vulnerability has been resolved: iio: core: fix uninitialized data in debugfs If *p...
CVE-2026-68088In the Linux kernel, the following vulnerability has been resolved: usb: gadget: function: rndis: add length check to r...
CVE-2026-68087In the Linux kernel, the following vulnerability has been resolved: HID: wacom: use GFP_ATOMIC in wacom_wac_queue_flush...
CVE-2026-68086In the Linux kernel, the following vulnerability has been resolved: mm/khugepaged: write all dirty file folios when col...
CVE-2026-68085In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: clear HCI_UART_SENDING when wr...
CVE-2026-68084In the Linux kernel, the following vulnerability has been resolved: staging: vme_user: fix location monitor leak in tsi...
CVE-2026-68083In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix path resolution in ksmbd_vfs_kern_path_c...
CVE-2026-64941LOW2.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in phoenixframework phoenix_live_view allows an attack...
CVE-2026-59088MEDIUM5.5A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI im...
CVE-2026-72594HIGH7.6A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authentic...
CVE-2026-72593CRITICAL9.8A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to acce...
CVE-2026-72592CRITICAL9.8An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to e...
CVE-2026-72591HIGH7.7A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make t...
CVE-2026-72590CRITICAL9.8An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker...
CVE-2026-72589CRITICAL9.8An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker...
CVE-2026-72588MEDIUM5.3A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to d...
CVE-2026-72587MEDIUM6.1A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remote attacker to poison...
CVE-2026-72586HIGH7.5A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to que...
CVE-2026-72585MEDIUM6.5An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete protected contact p...
CVE-2026-72584HIGH7.4A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an unauthenticated remote attac...
CVE-2026-72583MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in fastschema through v0.15.1 allows a low-privileged authenticated us...
CVE-2026-72582HIGH7.5A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to cras...
CVE-2026-72581HIGH8.6A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker...