CVE Vulnerability Database

Search and browse 390,037 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-59895MEDIUM6.1Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in...
CVE-2026-59892HIGH7.5OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. Prior to 2.9.0, @opentelemetry/propagator-jaeger decode...
CVE-2026-59890MEDIUM6.1setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to ...
CVE-2026-59887HIGH7.5linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used b...
CVE-2026-59883MEDIUM6.1Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bar...
CVE-2026-59882MEDIUM6.5guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not ...
CVE-2026-59879HIGH7.5Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#...
CVE-2026-59731HIGH8.2Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially deco...
CVE-2026-59261MEDIUM6.5OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provide...
CVE-2026-42505MEDIUM5.3Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of...
CVE-2026-39822HIGH7.8On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina...
CVE-2026-29009CRITICAL9.8U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFI...
CVE-2026-29008HIGH8.7U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c...
CVE-2026-29007MEDIUM6.9U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFI...
CVE-2025-3110HIGH7.5OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote at...
CVE-2026-9074CRITICAL9.8IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulner...
CVE-2026-59880HIGH7.5Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, Immutable.Map and Immutable.S...
CVE-2026-59877HIGH7.5protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed opt...
CVE-2026-59876MEDIUM4.8protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text For...
CVE-2026-59875MEDIUM5.3node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX ...
CVE-2026-59874HIGH7.5node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar he...
CVE-2026-59873HIGH7.5node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds...
CVE-2026-59871HIGH7.5node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and lin...
CVE-2026-59870HIGH7.5js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.1, YAML11_SCHEMA support for the !!omap tag in src...
CVE-2026-59869HIGH7.5js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend ...