CVE Vulnerability Database
Search and browse 394,279 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28898 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing t... |
| CVE-2026-12921 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | In AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by an attacker using spe... |
| CVE-2026-12897 | HIGH | 8.4 | 0.1% | Jun 25, 2026 | Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsin... |
| CVE-2026-6291 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData using RSA PKCS#1 v1.5 key ... |
| CVE-2026-6094 | CRITICAL | 9.1 | 0.3% | Jun 25, 2026 | Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically ... |
| CVE-2026-6091 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | Partial-chain certificate verification may accept chains that terminate at a peer-supplied, untrusted intermediate certi... |
| CVE-2026-55967 | HIGH | 7.5 | 0.1% | Jun 25, 2026 | AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected ... |
| CVE-2026-55961 | HIGH | 7.5 | 0.1% | Jun 25, 2026 | wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) PKCS#7 object that contains no signer. Such an ob... |
| CVE-2026-55700 | HIGH | 7.1 | 0.3% | Jun 25, 2026 | pnpm is a package manager. From 11.3.0 until 11.5.3, `pnpm stage download` derived a local filename from registry-contro... |
| CVE-2026-55699 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.2 and 11.5.3, Manifest bin object keys such as "", ".", and ".." passed pnpm's... |
| CVE-2026-55698 | HIGH | 8.8 | 0.2% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first... |
| CVE-2026-55697 | HIGH | 8.8 | 0.1% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.y... |
| CVE-2026-55487 | HIGH | 8.8 | 0.1% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized t... |
| CVE-2026-55180 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repositor... |
| CVE-2026-54679 | MEDIUM | 5.5 | 0.1% | Jun 25, 2026 | jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple... |
| CVE-2026-50573 | HIGH | 8.1 | 0.1% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package ... |
| CVE-2026-50021 | HIGH | 8.1 | 0.1% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification wh... |
| CVE-2026-50017 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials... |
| CVE-2026-50016 | HIGH | 8.8 | 0.3% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package ... |
| CVE-2026-50015 | HIGH | 7.3 | 0.3% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch application pipeline (@pnpm/patch-package) performs... |
| CVE-2026-50014 | HIGH | 7.3 | 0.2% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value ... |
| CVE-2026-49839 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into inval... |
| CVE-2026-48995 | HIGH | 7.5 | 0.1% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarbal... |
| CVE-2026-47770 | MEDIUM | 5.5 | 0.1% | Jun 25, 2026 | jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operato... |
| CVE-2026-11999 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_... |
