CVE Vulnerability Database

Search and browse 394,250 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-37454HIGH7.5Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensit...
CVE-2026-37453HIGH7.5Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensit...
CVE-2026-37149HIGH7.7GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerabil...
CVE-2026-2299MEDIUM4.3The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoi...
CVE-2026-12340HIGH7.5Out-of-bounds heap read during SM2/SM3 certificate signature verification. When parsing a certificate with an SM3wSM2 si...
CVE-2026-11310HIGH7.5X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects on...
CVE-2026-10592MEDIUM5.3Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA name-constraint checks. A certificate with a wildca...
CVE-2026-10512HIGH7.5The X25519 x86_64 assembly implementation fails to clear the most significant bit during the final modular reduction, so...
CVE-2026-10097HIGH7.5wolfSSL's AVX2-optimized ML-KEM implementation (mlkem_cmp_avx2) compares only 1536 of the 1568 ciphertext bytes during t...
CVE-2025-60465MEDIUM6.1A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02...
CVE-2025-60464HIGH7.8A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26....
CVE-2026-57700CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This i...
CVE-2026-56790HIGH7.3CANBoat through 6.22, fixed in commit a5a22b7, contains an off-by-one global buffer overflow in the searchForPgn() funct...
CVE-2026-56789HIGH7.1RTKLIB through 2.4.3 contains a heap buffer overflow vulnerability in the readrnxobsb function in src/rinex.c that allow...
CVE-2026-56788HIGH7.1RTKLIB through 2.4.3 contains an out-of-bounds read vulnerability in getcodepri function when processing unrecognized RI...
CVE-2026-56787HIGH7.5RTKLIB through 2.4.3 contains an off-by-one out-of-bounds read vulnerability in the decode_ssr3 function at src/rtcm3.c:...
CVE-2026-56786CRITICAL9.8RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp lengt...
CVE-2026-56779MEDIUM6.4MaxKB before 2.10.0 contains a server-side request forgery vulnerability in tool creation and update endpoints that allo...
CVE-2026-56774MEDIUM5.4Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id par...
CVE-2026-56772MEDIUM5.3NewsBlur before 14.5.0 contains a broken access control vulnerability that allows authenticated users to read private no...
CVE-2026-56771HIGH8.5NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows ...
CVE-2026-56770HIGH7.5libais through 0.15 VdmStream::AddLine uses an unchecked sentinel value as a vector index when processing AIS sentences ...
CVE-2026-56769HIGH8.5Huly Platform through 0.7.423, fixed in commit 68cbf8a contains an authenticated server-side request forgery vulnerabili...
CVE-2026-56768HIGH8.8Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthe...
CVE-2026-56767HIGH8.8Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API ha...