CVE Vulnerability Database

Search and browse 390,072 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-21369MEDIUM5.3Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.
CVE-2026-21368MEDIUM5.3Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.
CVE-2026-14471HIGH8.6Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-g...
CVE-2026-14468HIGH7.7HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that...
CVE-2025-59617HIGH7.3Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.
CVE-2025-59616HIGH7.8Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing alrea...
CVE-2025-59615HIGH7.8Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffe...
CVE-2026-59089MEDIUM5.5A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calc...
CVE-2026-58404MEDIUM6.8Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests t...
CVE-2026-58403MEDIUM6.5Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's virtual filesystem is designed so that files und...
CVE-2026-58402MEDIUM5.4Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-f...
CVE-2026-55646MEDIUM6.5vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions a...
CVE-2026-53763LOW3.8OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-50134MEDIUM5.8Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.http.urls on the URL i...
CVE-2026-50133MEDIUM6.1Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to...
CVE-2026-44362MEDIUM5.5OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-42546LOW3.8OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-41516LOW3.3OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-41515LOW3.3OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-41514LOW3.3OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-14898MEDIUM6.5The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could pl...
CVE-2026-14536HIGH8.8Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attack...
CVE-2026-11405CRITICAL9.8The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8...
CVE-2026-9182CRITICAL9.8Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this is...
CVE-2026-9181HIGH7.5Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An una...