CVE Vulnerability Database
Search and browse 394,250 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71327 | CRITICAL | 9.3 | 0.5% | Jun 25, 2026 | Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows... |
| CVE-2025-71324 | HIGH | 8.7 | 0.3% | Jun 25, 2026 | Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-fil... |
| CVE-2021-47987 | HIGH | 7.7 | 0.1% | Jun 25, 2026 | Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the of... |
| CVE-2021-47986 | HIGH | 7.7 | 0.1% | Jun 25, 2026 | Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the reposit... |
| CVE-2020-37256 | MEDIUM | 5.4 | 0.2% | Jun 25, 2026 | Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security config... |
| CVE-2026-6731 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN... |
| CVE-2026-6681 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written... |
| CVE-2026-6679 | HIGH | 7.5 | 0.4% | Jun 25, 2026 | A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. T... |
| CVE-2026-6678 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handlin... |
| CVE-2026-6450 | MEDIUM | 5.3 | 0.1% | Jun 25, 2026 | A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allow... |
| CVE-2026-6412 | MEDIUM | 4.3 | 0.1% | Jun 25, 2026 | Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate proce... |
| CVE-2026-56445 | CRITICAL | 9.1 | 0.4% | Jun 25, 2026 | The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.pa... |
| CVE-2026-38640 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a De... |
| CVE-2026-38637 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of S... |
| CVE-2026-37452 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensit... |
| CVE-2026-12473 | HIGH | 8.3 | 0.2% | Jun 25, 2026 | Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter wit... |
| CVE-2026-7531 | CRITICAL | 9.8 | 0.3% | Jun 25, 2026 | Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1... |
| CVE-2026-57522 | MEDIUM | 5 | 0.3% | Jun 25, 2026 | Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens()... |
| CVE-2026-57521 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to ac... |
| CVE-2026-57520 | HIGH | 7.1 | 0.4% | Jun 25, 2026 | Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users wi... |
| CVE-2026-55964 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to ha... |
| CVE-2026-55960 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw pub... |
| CVE-2026-55958 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding th... |
| CVE-2026-46602 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image cont... |
| CVE-2026-46601 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. |
