CVE Vulnerability Database

Search and browse 390,151 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-36912HIGH7.5A NULL pointer dereference in the AP4_AtomSampleTable::GetSample() function of Aleksoid1978 MPC-BE before commit 4341cb3...
CVE-2026-36911MEDIUM5.5A division-by-zero vulnerability in the CStreamSwitcherOutputPin::DecideBufferSize function of Aleksoid1978 MPC-BE befor...
CVE-2026-36910MEDIUM5.5An access violation in the BaseSplitterFile::Read function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers...
CVE-2026-36909MEDIUM6.2A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allow...
CVE-2026-58263HIGH7.2Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. In versions prior to 4.12.28, the built-in...
CVE-2026-55886MEDIUM6.3Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. Versions prior to ...
CVE-2026-55661MEDIUM4.8Tina is a headless content management system. In versions prior to @tinacms/mdx 2.1.7 and tinacms 3.9.3, rich-text par...
CVE-2026-55660HIGH7.6Tina is a headless content management system. In versions prior to @tinacms/app 2.5.6 and tinacms 3.9.3, cross-origin po...
CVE-2026-55153HIGH7.1mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool....
CVE-2026-54786MEDIUM5Wasmtime is a runtime for WebAssembly. All versions prior to 24.0.10; versions 25.0.0 through those before 36.0.11; ver...
CVE-2026-54756MEDIUM6.3Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. In versions prior ...
CVE-2026-54720MEDIUM5.4Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In versions prior to 6.2.2, the "Insert med...
CVE-2026-54074HIGH7.8Tina is a headless content management system. @tinacms/cli versions prior to 2.4.3 contain a Remote Code Execution vulne...
CVE-2026-50521HIGH8.3Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
CVE-2026-14340MEDIUM5An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token ...
CVE-2026-58593HIGH8.7NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound ...
CVE-2026-58592HIGH8.3Ladybird before commit 2f9dc7e contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration modul...
CVE-2026-58457CRITICAL9.8Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability...
CVE-2026-55688MEDIUM4The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT...
CVE-2026-54908MEDIUM6.3Pion DTLS is a Go implementation of Datagram Transport Layer Security. Versions prior to 3.1.4 are vulnerable to Remote ...
CVE-2026-54164MEDIUM6.5API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions prior to 4.1.30, 4.2.26 and...
CVE-2026-49858MEDIUM5.9API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions from 2.6.0 prior to 4.1.29,...
CVE-2026-14363CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foun...
CVE-2026-14265HIGH8.8Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 t...
CVE-2026-58517MEDIUM4.3Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension ...