CVE Vulnerability Database

Search and browse 394,250 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-71327CRITICAL9.3Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows...
CVE-2025-71324HIGH8.7Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-fil...
CVE-2021-47987HIGH7.7Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the of...
CVE-2021-47986HIGH7.7Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the reposit...
CVE-2020-37256MEDIUM5.4Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security config...
CVE-2026-6731HIGH7.5X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN...
CVE-2026-6681MEDIUM5.3The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written...
CVE-2026-6679HIGH7.5A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. T...
CVE-2026-6678MEDIUM5.3Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handlin...
CVE-2026-6450MEDIUM5.3A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allow...
CVE-2026-6412MEDIUM4.3Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate proce...
CVE-2026-56445CRITICAL9.1The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.pa...
CVE-2026-38640HIGH7.5A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a De...
CVE-2026-38637HIGH7.5An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of S...
CVE-2026-37452HIGH7.5Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensit...
CVE-2026-12473HIGH8.3Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter wit...
CVE-2026-7531CRITICAL9.8Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1...
CVE-2026-57522MEDIUM5Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens()...
CVE-2026-57521MEDIUM5.3Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to ac...
CVE-2026-57520HIGH7.1Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users wi...
CVE-2026-55964MEDIUM5.3Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to ha...
CVE-2026-55960HIGH7.5Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw pub...
CVE-2026-55958HIGH7.5Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding th...
CVE-2026-46602HIGH7.5The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image cont...
CVE-2026-46601HIGH7.5The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size.