CVE Vulnerability Database

Search and browse 394,851 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-55643MEDIUM5.5A NULL pointer dereference in the TrackWriter handling component (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attacke...
CVE-2025-55642MEDIUM6.5GPAC MP4Box v2.4 was discovered to contain a floating point exception in the avidmx_process function (isomedia/isom_writ...
CVE-2025-55641MEDIUM5.5A NULL pointer dereference in the gf_isom_copy_sample_info function (isomedia/isom_write.c) of GPAC MP4Box v2.4 allows a...
CVE-2026-8358MEDIUM5.4LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document ...
CVE-2026-8357HIGH7.8LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very...
CVE-2026-8356MEDIUM5.4LibreOffice can import presentations in the legacy binary PPT format. A stack buffer overflow existed when importing a c...
CVE-2026-6047MEDIUM5.4LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred pars...
CVE-2026-6045MEDIUM5.4LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing ...
CVE-2026-6040HIGH7.3A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read f...
CVE-2026-6039MEDIUM5.4LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a ...
CVE-2026-49294MEDIUM6.1Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. Versions 3.6.3 and...
CVE-2026-47777HIGH7.5Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in ...
CVE-2026-20262MEDIUM6.5A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r...
CVE-2026-9863HIGH8.8Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy ta...
CVE-2026-9862CRITICAL9.8Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd...
CVE-2026-9595MEDIUM4.3Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts...
CVE-2026-8683MEDIUM6.5Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Matterm...
CVE-2026-5038HIGH7.5Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using d...
CVE-2026-10634MEDIUM5.3Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using the SYS_S...
CVE-2025-15659MEDIUM6.5Contributor Cross Site Scripting (XSS) in Elizaibots <= 1.0.2 versions.
CVE-2025-15658MEDIUM5.9Administrator Cross Site Scripting (XSS) in WP Emmet <= 0.3.4 versions.
CVE-2026-6517HIGH7.7Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were...
CVE-2026-5242HIGH8.8Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy Library allows Code...
CVE-2026-5233HIGH7.1Improper Control of Interaction Frequency vulnerability in MIA Technology Inc. Pizzy Library allows Flooding. This issu...
CVE-2026-5230HIGH7.1Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library allows Exploiting Inco...