CVE Vulnerability Database

Search and browse 394,279 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-28898MEDIUM5.3swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing t...
CVE-2026-12921HIGH7.8In AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by an attacker using spe...
CVE-2026-12897HIGH8.4Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsin...
CVE-2026-6291MEDIUM6.5Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData using RSA PKCS#1 v1.5 key ...
CVE-2026-6094CRITICAL9.1Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically ...
CVE-2026-6091MEDIUM6.5Partial-chain certificate verification may accept chains that terminate at a peer-supplied, untrusted intermediate certi...
CVE-2026-55967HIGH7.5AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected ...
CVE-2026-55961HIGH7.5wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) PKCS#7 object that contains no signer. Such an ob...
CVE-2026-55700HIGH7.1pnpm is a package manager. From 11.3.0 until 11.5.3, `pnpm stage download` derived a local filename from registry-contro...
CVE-2026-55699MEDIUM6.5pnpm is a package manager. Prior to 10.34.2 and 11.5.3, Manifest bin object keys such as "", ".", and ".." passed pnpm's...
CVE-2026-55698HIGH8.8pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first...
CVE-2026-55697HIGH8.8pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.y...
CVE-2026-55487HIGH8.8pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized t...
CVE-2026-55180MEDIUM6.5pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repositor...
CVE-2026-54679MEDIUM5.5jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple...
CVE-2026-50573HIGH8.1pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package ...
CVE-2026-50021HIGH8.1pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification wh...
CVE-2026-50017MEDIUM6.5pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials...
CVE-2026-50016HIGH8.8pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package ...
CVE-2026-50015HIGH7.3pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch application pipeline (@pnpm/patch-package) performs...
CVE-2026-50014HIGH7.3pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value ...
CVE-2026-49839HIGH7.1jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into inval...
CVE-2026-48995HIGH7.5pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarbal...
CVE-2026-47770MEDIUM5.5jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operato...
CVE-2026-11999HIGH7.5X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_...