CVE Vulnerability Database

Search and browse 390,364 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-6556CRITICAL9.1@fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argu...
CVE-2026-58374HIGH7.1In hostapd before 2.12, a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) Multi-Link Operation (MLO) association...
CVE-2026-58116HIGH8.8LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to ex...
CVE-2026-58016CRITICAL9.1A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection...
CVE-2026-58015HIGH7.5A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism doe...
CVE-2026-58014HIGH8.6A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfil...
CVE-2026-58013HIGH8.2A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when...
CVE-2026-58012HIGH8.2A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` ...
CVE-2026-58011HIGH7.5A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the gli...
CVE-2026-58010HIGH8.2A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-seriali...
CVE-2026-53433HIGH7.5fzf is vulnerable to a Denial of Service (DoS) due to inefficient HTTP body processing in the --listen mode due to ineff...
CVE-2026-53432HIGH7.5fzf is vulnerable to Integer Overflow leading to crash in FuzzyMatchV2 function. When input line length is approximately...
CVE-2026-4629MEDIUM6.5A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability b...
CVE-2026-47105Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-44946HIGH7.4A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-t...
CVE-2026-14209MEDIUM4.3A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to bypass secur...
CVE-2026-13474HIGH7.5Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Prof...
CVE-2026-12388MEDIUM6.5A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user informati...
CVE-2026-10817HIGH7.5Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is ...
CVE-2026-10816HIGH7.5Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management I...
CVE-2026-8402CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electroni...
CVE-2026-57082MEDIUM5.9Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG...
CVE-2026-57081HIGH7.5Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecod...
CVE-2026-57080HIGH7.5Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length ...
CVE-2026-57079MEDIUM5.3Net::BitTorrent versions before 2.1.0 for Perl write files outside the download directory via path traversal in peer-sup...