CVE Vulnerability Database

Search and browse 394,250 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-6330MEDIUM6.5The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's i...
CVE-2026-6329MEDIUM6.5PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and all...
CVE-2026-6325HIGH7.5Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a write pas...
CVE-2026-6092MEDIUM5.3When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing E...
CVE-2026-55962MEDIUM6.5TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the cl...
CVE-2026-54479HIGH7.3The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ...
CVE-2026-50176HIGH8.7The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc...
CVE-2026-44622MEDIUM6.9Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-40702CRITICAL9.4WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a res...
CVE-2026-22879HIGH8.1vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability
CVE-2026-13283HIGH7.5Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a...
CVE-2026-13282MEDIUM6.8Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially e...
CVE-2026-13281HIGH8.3Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the rend...
CVE-2026-12992HIGH7.4A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.ws...
CVE-2026-12975HIGH8.5A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without ena...
CVE-2026-11800HIGH8.1A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an a...
CVE-2026-11703HIGH7.5Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for t...
CVE-2026-10098MEDIUM5.3OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose se...
CVE-2025-71340HIGH8.1picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode...
CVE-2025-71338CRITICAL9.8Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated at...
CVE-2025-71336CRITICAL9.8Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnera...
CVE-2025-71335HIGH8.6Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens aft...
CVE-2025-71334CRITICAL9.8Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missin...
CVE-2025-71333CRITICAL9.8Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoin...
CVE-2025-71328HIGH8.8Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their accou...