CVE Vulnerability Database

Search and browse 392,387 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-51219HIGH7.5A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows...
CVE-2026-51218HIGH7.5A heap buffer overflow in the TS7Worker::PerformFunctionWrite() function (/core/s7_server.cpp) of snap7 v1.4.3 allows at...
CVE-2026-10648MEDIUM5.5mcumgr_serial_process_frag() in subsys/mgmt/mcumgr/transport/src/serial_util.c calls net_buf_reset() on the result of sm...
CVE-2026-57997MEDIUM5.4Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not exp...
CVE-2026-51221HIGH7.5A buffer overflow in the Get_Attribute_List function of EIPStackGroup OpENer commit 76b95c allows attackers to cause a D...
CVE-2026-34592HIGH7.7Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-10647MEDIUM5.3The USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_ncm.c) ignores the return value of usbd_ep_enqueue()...
CVE-2026-55957HIGH7.3Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate...
CVE-2026-55956MEDIUM6.5Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ig...
CVE-2026-55955MEDIUM6.5Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the ...
CVE-2026-55276CRITICAL9.1Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisa...
CVE-2026-53434CRITICAL9.1Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connect...
CVE-2026-53404HIGH7.3Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first cond...
CVE-2026-50229MEDIUM6.1Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example ...
CVE-2026-41896HIGH7.5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34597HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34594HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-13758LOW3.7CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt...
CVE-2026-57919HIGH7.8PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DA...
CVE-2026-57498CRITICAL9.6Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-56018HIGH7.5JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory ...
CVE-2026-56017HIGH7.5JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL pointer dereference when the first meaningful t...
CVE-2026-54889MEDIUM5.1Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in leandrocp mdex allows cross-site scri...
CVE-2026-54888MEDIUM6.9Uncontrolled Recursion vulnerability in leandrocp mdex allows denial of service via deeply nested Markdown input. mdex ...
CVE-2026-53429MEDIUM6.9Missing Release of Memory after Effective Lifetime vulnerability in leandrocp mdex and mdex_native allows an attacker wh...