CVE Vulnerability Database

Search and browse 394,603 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-54268HIGH7.5Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-54267MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-54266MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-54265MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-54264MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-53655MEDIUM5.5node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= recor...
CVE-2026-53550MEDIUM5.3js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithm...
CVE-2026-52725MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-50557MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-50178HIGH8.8The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side...
CVE-2026-49241HIGH8.8The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4...
CVE-2026-41049HIGH7.1Incorrect caching of authentication between different users of the  qSnapper dbus service before version 1.3.3 allowed a...
CVE-2026-41048HIGH7.1Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local at...
CVE-2026-41047MEDIUM5.5Lack of authentication when using the "snapshot diff" functions in qSnapper before version 1.3.3 allowed a local attacke...
CVE-2026-41046HIGH7.3A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to...
CVE-2026-41045HIGH7A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass...
CVE-2026-12725MEDIUM5.9A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of...
CVE-2026-12628CRITICAL9.1IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 ...
CVE-2026-12549MEDIUM4.8The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a gene...
CVE-2026-12479MEDIUM6.1A path traversal vulnerability exists in keras-team/keras version 3.14.0, specifically in the `DiskIOStore.make` method ...
CVE-2026-11943MEDIUM4.8Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the document timeline shown on i...
CVE-2026-11942MEDIUM4.8Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the reusable delete confirmation...
CVE-2026-11372MEDIUM5.4IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an...
CVE-2026-10845HIGH7.3IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorize...
CVE-2024-51454MEDIUM6.1IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 th...