CVE Vulnerability Database

Search and browse 394,557 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-48510HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, when MessagePack-CSharp decompresses ...
CVE-2026-48509CRITICAL9.1MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFor...
CVE-2026-48506HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.TrySkip() recursive...
CVE-2026-48505HIGH7.4Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5...
CVE-2026-48502HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can ...
CVE-2026-48500MEDIUM6.5Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, ...
CVE-2026-48167MEDIUM6.4Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5...
CVE-2026-48166MEDIUM5.3Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5...
CVE-2026-48109HIGH8.2MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, A vulnerability exists in the optiona...
CVE-2026-48067MEDIUM6.5Filament is a collection of full-stack components for accelerated Laravel development. From filament/actions 4.0.0 until...
CVE-2026-44889MEDIUM6.1WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header d...
CVE-2026-44311MEDIUM6.1Fabric.js is a Javascript HTML5 canvas library. Prior to 7.4.0, a potential Cross-Site Scripting (XSS) vulnerability exi...
CVE-2025-71358HIGH8.1picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.autocomplete.AutoComplete.get_entit...
CVE-2025-71344HIGH8.1picklescan before 0.0.30 (affected versions 0.0.26 and earlier) fails to detect the ensurepip._run_pip built-in function...
CVE-2025-71339HIGH8.1Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran._eval_length gadget in pickle __reduce__ methods, a...
CVE-2026-55603HIGH7.5http-proxy-middleware is node.js http-proxy middleware. From 3.0.4 until 3.0.7 and 4.1.1, fixRequestBody() is the librar...
CVE-2026-55599MEDIUM5.8phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application valid...
CVE-2026-54651MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.13.1, an attacker who uses this vulnerability can cr...
CVE-2026-54531MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can cr...
CVE-2026-54530MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can cr...
CVE-2026-49468CRITICAL9.8LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header par...
CVE-2026-49461MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can cr...
CVE-2026-49460LOW3.3pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can cr...
CVE-2026-47242MEDIUM5.8Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, wh...
CVE-2026-47241LOW2.1Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, se...