CVE Vulnerability Database

Search and browse 394,735 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-48140HIGH7.1There is an unchecked enum cast vulnerability in NI grpc-device BeginSidebandStream that may allow an attacker to trigge...
CVE-2026-48139HIGH8.7There is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that may allow an attack...
CVE-2026-48138HIGH8.7There is an out-of-bounds read vulnerability in the NI grpc-device streaming API due to a missing bounds check that may ...
CVE-2026-48137CRITICAL9.8There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an a...
CVE-2026-47341MEDIUM6.5Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from certain configuration...
CVE-2026-47339HIGH8.1Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under defaul...
CVE-2026-44915MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-au...
CVE-2026-44087CRITICAL9.1Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default ...
CVE-2026-44046MEDIUM5.8Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac plugin under defaul...
CVE-2026-39999CRITICAL9.1Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication cap...
CVE-2026-39998HIGH8.8Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in f...
CVE-2026-12104HIGH8.6OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25....
CVE-2025-62821CRITICAL9.1Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return suc...
CVE-2026-56142HIGH8.8In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privileg...
CVE-2026-56141CRITICAL9.8In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account ...
CVE-2026-53915HIGH8.8In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration
CVE-2026-50242CRITICAL9.8In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authenti...
CVE-2026-44939CRITICAL9.4A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clus...
CVE-2026-12706MEDIUM6.5A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function initializes a read p...
CVE-2026-11941MEDIUM5.6Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The “...
CVE-2026-8296MEDIUM5.6In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payloa...
CVE-2026-56138MEDIUM5.3AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item iden...
CVE-2026-41156HIGH7.7Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reso...
CVE-2026-34192HIGH7.7Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an error path leading...
CVE-2026-11576HIGH7.5The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process t...