CVE Vulnerability Database

Search and browse 390,222 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-58399HIGH8.7@acastellon/auth is an authentication control system for microservices. Versions prior to 2.3.0 appear to allow an unaut...
CVE-2026-58035MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-58034MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-58031MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-2891HIGH8.2The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP serve...
CVE-2026-23537CRITICAL9.1A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticat...
CVE-2026-14330MEDIUM5.5Multiple unbounded alloca() calls in the PulseAudio protocol server.
CVE-2026-14324MEDIUM6.5RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
CVE-2026-13602HIGH7.7We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the ...
CVE-2026-12374MEDIUM6.4Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC ...
CVE-2026-5136HIGH8.8A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the call...
CVE-2026-57692CRITICAL9.8Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects Pr...
CVE-2026-53356HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Fix phys BO pread/pwrite with offset ...
CVE-2026-53355CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB...
CVE-2026-53354HIGH8.8In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Mitigate TLBI errata on various Arm ...
CVE-2026-53353MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: hsr: Remove WARN_ONCE() in hsr_addr_is_self(). syz...
CVE-2026-53352MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: signal: clear JOBCTL_PENDING_MASK for caller in zap...
CVE-2026-53351MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: riscv/ptrace: Use USER_REGSET_NOTE_TYPE for REGSET_...
CVE-2026-53350MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ASoC: wm_adsp: Fix NULL dereference when removing f...
CVE-2026-53349MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: destroy stale expectfn exp...
CVE-2026-53348In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: fix NULL pointer dereference in sdca_de...
CVE-2026-53347In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix driver removal with disabled KMS D...
CVE-2026-53346In the Linux kernel, the following vulnerability has been resolved: rust: arm64: set uwtable llvm module flag for CONFI...
CVE-2026-53345In the Linux kernel, the following vulnerability has been resolved: KVM: Don't WARN if memory is dirtied without a vCPU...
CVE-2026-53344MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: pinctrl: mcp23s08: Initialize mcp->dev and mcp->add...