CVE Vulnerability Database

Search and browse 393,242 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-24243HIGH7.8NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted dat...
CVE-2026-24242HIGH7.8NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause server-side request forgery. A s...
CVE-2026-24240HIGH7.8NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted dat...
CVE-2026-13707HIGH7.6Session fixation vulnerability in Wikimedia Foundation OAuth. This vulnerability is associated with program files src/...
CVE-2026-13706HIGH8.8Improper input validation vulnerability in Wikimedia Foundation UrlShortener. This vulnerability is associated with pr...
CVE-2025-23351CRITICAL9NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function ...
CVE-2025-23350CRITICAL9NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function ...
CVE-2025-15646CRITICAL9.8HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the <template> element w...
CVE-2026-6688HIGH7.6FatFs R0.16 and earlier contains a downstream-caller vulnerability pattern associated with FatFs long filename handling....
CVE-2026-6687HIGH7.6FatFs R0.16 and earlier contains a stack overflow bug in f_getlabel() because exFAT label length (XDIR_NumLabel) is trus...
CVE-2026-6686MEDIUM4.6FatFs R0.16 and earlier contains an uninitialized cluster exposure when f_lseek() extends files beyond EOF without zero-...
CVE-2026-6685Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority following a notification that...
CVE-2026-6684MEDIUM4.6FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded loop count derived f...
CVE-2026-6683MEDIUM4.6FatFs R0.16 and earlier contains a divide-by-zero in exFAT sync logic bug when crafted metadata causes n_fatent - 2 to b...
CVE-2026-6682HIGH7.6In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= fs->n_fats can wrap, ...
CVE-2026-6283MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Informa...
CVE-2026-5220MEDIUM6.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Informa...
CVE-2026-5142MEDIUM6.5A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing t...
CVE-2026-5138MEDIUM4.3A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information d...
CVE-2026-5135MEDIUM6.5A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permis...
CVE-2026-58399HIGH8.7@acastellon/auth is an authentication control system for microservices. Versions prior to 2.3.0 appear to allow an unaut...
CVE-2026-58035MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-58034MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-58031MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-2891HIGH8.2The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP serve...