CVE Vulnerability Database

Search and browse 391,091 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-20458HIGH7.5In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote escalation of p...
CVE-2026-20457MEDIUM5.3In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service...
CVE-2026-14191HIGH7.8An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeade...
CVE-2026-57963MEDIUM6.5An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, an...
CVE-2026-57962MEDIUM5.3A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitr...
CVE-2026-53488HIGH8.8containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plu...
CVE-2026-41579LOW3.3runc is a CLI tool for spawning and running containers according to the OCI specification. In versions prior to 1.3.6, 1...
CVE-2026-54903MEDIUM6.3Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.load ...
CVE-2026-54902MEDIUM6.3Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to version 3.17.2, is vulnerabl...
CVE-2026-54901MEDIUM6.3Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj::Pars...
CVE-2026-54900MEDIUM6.3Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, when in ...
CVE-2026-54899MEDIUM6.3Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to version 3.17.2, disabling sy...
CVE-2026-54898LOW2.1Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2,Oj::Parse...
CVE-2026-54897LOW2.1Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to 3.17.2, Oj::Doc iterators (e...
CVE-2026-54896LOW2.1Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, when in ...
CVE-2026-54592HIGH7.5Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj::Doc#...
CVE-2026-54502MEDIUM6.3Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.dump ...
CVE-2026-54500MEDIUM5.3Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load ...
CVE-2026-57995HIGH8.8phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GR...
CVE-2026-56777MEDIUM5.3n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in the Pytho...
CVE-2026-56700CRITICAL9.8Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Sch...
CVE-2026-56415CRITICAL10Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable...
CVE-2026-56413CRITICAL10Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens ...
CVE-2026-56399MEDIUM5.3Open WebUI before 0.6.27 contains a server-side request forgery vulnerability in the /api/v1/retrieval/process/web endpo...
CVE-2026-56377MEDIUM4.8ImageMagick before 7.1.2-24 contains an incorrect policy check that allows attackers to create or truncate files disallo...