CVE Vulnerability Database

Search and browse 394,832 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-10748HIGH8.6An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbi...
CVE-2024-39575HIGH7.4update_disk_psu_baseline.sh requires password in plain text
CVE-2026-53776CRITICAL9.3Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by...
CVE-2026-44932HIGH8.8Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attac...
CVE-2026-42089HIGH8.6Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator i...
CVE-2026-39927Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-39926Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-24228HIGH7.8NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. ...
CVE-2026-24155HIGH7.8NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerabil...
CVE-2026-12412Rejected reason: loading template...
CVE-2026-12003MEDIUM5.3To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is...
CVE-2026-10649HIGH8.6A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the r...
CVE-2025-71261HIGH8.6An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8....
CVE-2024-38487HIGH7api-gateway container running with root privilege would allow an attacker to escape the container and access host system...
CVE-2024-30476MEDIUM5.4PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager. A remote authenticated low-pr...
CVE-2024-24909HIGH8.8Dell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in the ga...
CVE-2024-22451MEDIUM6.7Dell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolled search path element vulnerability. An att...
CVE-2026-9307MEDIUM6.3A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's ...
CVE-2026-48780HIGH8.2Forem is open source software for building communities. Prior to commit a2ab6d4, a maliciously crafted email address cou...
CVE-2026-47684HIGH7.7Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version...
CVE-2026-12398HIGH7.5A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (...
CVE-2026-11317HIGH8.7A denial of service security issue exists in the affected product. The security issue stems from a fault occurring when ...
CVE-2026-10831MEDIUM6.9A denial-of-service vulnerability exists in NPort devices because of improper access control on the command port. The co...
CVE-2026-10640HIGH7.1Zephyr's IPv6 Neighbor Discovery send paths (net_ipv6_send_na, net_ipv6_send_ns, net_ipv6_send_rs in subsys/net/ip/ipv6_...
CVE-2026-10639MEDIUM4.8In Zephyr's native IPv4 stack, icmpv4_handle_echo_request() in subsys/net/ip/icmpv4.c builds an echo-reply packet (reply...