CVE Vulnerability Database

Search and browse 375,697 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-68437In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fit paired fragment job in the cor...
CVE-2026-68436In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: use kvzalloc to allocate struct dc...
CVE-2026-68435In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix address space mismatch in kexec comm...
CVE-2026-68434In the Linux kernel, the following vulnerability has been resolved: serial: 8250_mid: Fix NULL function pointer derefer...
CVE-2026-68433In the Linux kernel, the following vulnerability has been resolved: libceph: bound get_version reply decode to front le...
CVE-2026-68432In the Linux kernel, the following vulnerability has been resolved: vxlan: require CAP_NET_ADMIN in the device netns fo...
CVE-2026-68431In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate minimum PDU size for transform requ...
CVE-2026-68430In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx8: drop unecessary BUG_ON() There's ...
CVE-2026-68429In the Linux kernel, the following vulnerability has been resolved: drm/dp_mst: Handle torn-down topology gracefully in...
CVE-2024-14043MEDIUM6.3A vulnerability was determined in Open5GS up to 2.7.1. This vulnerability affects the function mme_s6a_subscription_data...
CVE-2026-73250MEDIUM5.4Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the Notepad++ Windows 11 x64 and ARM64 installer...
CVE-2026-73249HIGH7.5calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{librar...
CVE-2026-73248HIGH8.5calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a ...
CVE-2026-73247HIGH8.6Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/cor...
CVE-2026-73246HIGH7.5Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kest...
CVE-2026-73245MEDIUM6.5Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/appli...
CVE-2026-68067CRITICAL9.8The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active...
CVE-2026-67568CRITICAL9.3The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from int...
CVE-2026-67558HIGH8.2The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match aga...
CVE-2026-66875HIGH8.8In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range...
CVE-2026-66340MEDIUM6.9The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout ...
CVE-2026-66098HIGH7.1The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the d...
CVE-2026-64934MEDIUM5.3The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, witho...
CVE-2026-5917CRITICAL9.6libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command inj...
CVE-2026-29036HIGH7.5cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointe...