CVE Vulnerability Database

Search and browse 390,079 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-5268CRITICAL9.1An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products li...
CVE-2026-59196HIGH7.1pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoiste...
CVE-2026-59195HIGH8.2pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependenc...
CVE-2026-59194HIGH7.1pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patch...
CVE-2026-59152MEDIUM5LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can se...
CVE-2026-58203MEDIUM5.3pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource rea...
CVE-2026-13122MEDIUM5.3OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service v...
CVE-2025-53830CRITICAL9.1Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud...
CVE-2025-53829HIGH8ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attack...
CVE-2025-53828HIGH8.5SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing appli...
CVE-2025-53827CRITICAL9.1ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classi...
CVE-2026-7185MEDIUM6A validation vulnerability has been identified in certain web features related to file management or upload in several p...
CVE-2026-58380HIGH7.8A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() ...
CVE-2026-54893LOW2.1URL path injection in the Microsoft Graph adapter of Swoosh. Swoosh.Adapters.MsGraph builds its Microsoft Graph API requ...
CVE-2026-13698HIGH7.5A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote a...
CVE-2026-13708HIGH7.5Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_...
CVE-2026-13705HIGH7.1Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bi...
CVE-2025-15668LOW3.3A vulnerability was identified in GPAC up to b40ce70f5. This issue affects the function sgpd_del_entry of the file src/i...
CVE-2025-15667LOW3.3A vulnerability was determined in GPAC up to 2.5-DEV. This vulnerability affects the function gf_isom_nalu_sample_rewrit...
CVE-2026-6901HIGH8.4Untrusted Search Path vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P...
CVE-2026-6900CRITICAL9.1Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before...
CVE-2026-58226HIGH8.7Inefficient Algorithmic Complexity vulnerability in elixir-mint hpax allows unauthenticated denial-of-service via unboun...
CVE-2026-56810HIGH8.7Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint (Mint.HTTP1 module) allows a deni...
CVE-2026-4249HIGH8.6The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient...
CVE-2026-49297HIGH8.1Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object ...