CVE Vulnerability Database

Search and browse 394,301 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-4526MEDIUM6.5In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logi...
CVE-2026-49506HIGH7.2Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted ...
CVE-2026-47154MEDIUM6.5In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating ...
CVE-2026-47153MEDIUM6.5In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-ze...
CVE-2026-47152MEDIUM6.5In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-ze...
CVE-2026-47151HIGH7.1In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock...
CVE-2026-47150HIGH7.1In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write a...
CVE-2026-47149MEDIUM6.5In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table re...
CVE-2026-47148MEDIUM6.5In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the me...
CVE-2026-47147HIGH7.1In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limi...
CVE-2026-47146MEDIUM6.5In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These ...
CVE-2026-47145MEDIUM6.5In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These ...
CVE-2026-46734HIGH7.8Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulner...
CVE-2026-46733HIGH7.8Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, contain an Improper Access Control vulnerabil...
CVE-2026-46732HIGH7Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resou...
CVE-2026-42390MEDIUM5.3An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured wit...
CVE-2026-42389MEDIUM5.3This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative ...
CVE-2026-42388MEDIUM5.9Incomplete validation of the SOA record present in a catalog zone might lead to a crash.
CVE-2026-42387MEDIUM5.9A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recur...
CVE-2026-41120CRITICAL9.8Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trust...
CVE-2026-40012MEDIUM5.3ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have...
CVE-2026-2815HIGH8.4Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys
CVE-2026-27366HIGH7.5Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions.
CVE-2026-12755LOW2.7Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows ...
CVE-2026-42004LOW3.7An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten ...