CVE Vulnerability Database

Search and browse 390,334 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-58446MEDIUM6.9Presenton before 0.8.8-beta bundles an MCP server that, on server/Docker deployments configured with session authenticat...
CVE-2026-57585HIGH7.5MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/cras...
CVE-2026-57204MEDIUM6.5pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An at...
CVE-2026-52868HIGH8.8An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area...
CVE-2026-52196HIGH7.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-50254HIGH8.7An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against store...
CVE-2026-50003CRITICAL9.8A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside th...
CVE-2026-37106CRITICAL9.8An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register functio...
CVE-2026-35505HIGH8.7An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. In single-process dep...
CVE-2026-11541CRITICAL9.8IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 an...
CVE-2026-10585MEDIUM5.4A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated att...
CVE-2026-9132MEDIUM6.5A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to r...
CVE-2026-9106MEDIUM5.5A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gai...
CVE-2026-44628HIGH8.7An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called...
CVE-2026-13207HIGH8.7FUXA versions 1.3.1 and prior contain an authentication bypass vulnerability via dot-segment path normalization in the R...
CVE-2026-11594MEDIUM6.1IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative ...
CVE-2026-10562MEDIUM5.9An unauthenticated URL redirection vulnerability has been identified in Archer AX20 V2 due to improper validation of use...
CVE-2025-36359MEDIUM6.5IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow...
CVE-2025-36336MEDIUM5.9IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to ob...
CVE-2025-36333MEDIUM4.3IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to perform unauthorized actio...
CVE-2025-36328MEDIUM4.3IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow a remote attacker to obtain sensitive information w...
CVE-2025-36327MEDIUM6.5IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to bypass security controls a...
CVE-2025-36324MEDIUM4.3IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 s vulnerable to server-side request forgery (SSRF). This may al...
CVE-2025-36323MEDIUM5.4IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to cross-site scripting. This vulnerability allow...
CVE-2025-36321MEDIUM5.7IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A remote attacker could inject...