CVE Vulnerability Database

Search and browse 390,037 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-44512MEDIUM5.5Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0,...
CVE-2026-44332MEDIUM5.3Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAu...
CVE-2026-36028MEDIUM6.8A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass...
CVE-2026-36027MEDIUM6.8An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a physically proximate attacker to execute arbitrary code via...
CVE-2026-15154MEDIUM6.5A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Ex...
CVE-2026-14891HIGH8.7HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job s...
CVE-2026-14373HIGH7.7HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host ...
CVE-2026-14361MEDIUM4.7The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template ...
CVE-2026-59938MEDIUM5.3pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared imag...
CVE-2026-59937HIGH7.5pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malf...
CVE-2026-50813MEDIUM6.1An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the S...
CVE-2026-50812MEDIUM5.5A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807...
CVE-2026-14362MEDIUM4.9HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling tha...
CVE-2026-60102HIGH8.8Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_Smb dri...
CVE-2026-59930MEDIUM4.3Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents direc...
CVE-2026-59929MEDIUM6.1Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/rende...
CVE-2026-59928HIGH7.5Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repe...
CVE-2026-59927MEDIUM5.3Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/dir...
CVE-2026-59926MEDIUM6.1Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/direc...
CVE-2026-59925HIGH7.5Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-ast...
CVE-2026-59924MEDIUM5.9Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes use...
CVE-2026-59923MEDIUM6.1Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block p...
CVE-2026-59922HIGH7.5Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or c...
CVE-2026-59897MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS...
CVE-2026-59896MEDIUM6.5Hono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/j...