CVE Vulnerability Database

Search and browse 394,250 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-57923HIGH7.5In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying pr...
CVE-2026-57922MEDIUM5.3In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
CVE-2026-57921HIGH7.5In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment te...
CVE-2026-53914CRITICAL9.8In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
CVE-2026-13426MEDIUM5.4The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path paramet...
CVE-2026-57920HIGH7.7Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certai...
CVE-2026-57915HIGH7.3It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized...
CVE-2026-40711HIGH8Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-po...
CVE-2025-64152CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issu...
CVE-2025-55017CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issu...
CVE-2026-57914MEDIUM6.5By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow ...
CVE-2026-57620MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclu...
CVE-2026-57918HIGH7.1libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c d...
CVE-2026-57913HIGH7.5Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transc...
CVE-2026-57912HIGH7.5Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes e...
CVE-2026-57473MEDIUM5.8A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911)...
CVE-2026-13325Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.
CVE-2025-7958HIGH7.1A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can exe...
CVE-2026-6658MEDIUM5.4A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized `text/vnd....
CVE-2026-1869MEDIUM6.5The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom U...
CVE-2026-11702HIGH7.5Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes. When an objec...
CVE-2026-11625HIGH7.5Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is in...
CVE-2026-57881CRITICAL9.8An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.1...
CVE-2026-57880CRITICAL9.8An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12...
CVE-2026-57879CRITICAL9.8An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12...