CVE Vulnerability Database

Search and browse 395,250 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-47131CRITICAL10vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__...
CVE-2026-46340HIGH7.5Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport...
CVE-2026-45674CRITICAL10Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-45673MEDIUM6.8Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-45536MEDIUM4Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-45416HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-44894HIGH7.5Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the toke...
CVE-2026-44893HIGH7.5Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior t...
CVE-2026-44205MEDIUM6.9Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerability in the user prof...
CVE-2026-41581MEDIUM6.9Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, there is a possible SQL Inject...
CVE-2026-10557CRITICAL9.8The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and a...
CVE-2026-28975MEDIUM6.9### Impact When `NIOHTTPRequestDecompressor` is configured with `.ratio(N)`, the decompression limit is enforced using ...
CVE-2026-28980HIGH8.7### Summary The `HTTPDecoder` in `NIOHTTP1` enforces no limit on the total size of an HTTP/1 message's header block or ...
CVE-2026-43671HIGH8.3### Summary A program using swift-nio is vulnerable to a potential out-of-bounds write when attacker-controlled index o...
CVE-2026-28970MEDIUM6.3Programs using swift-nio is vulnerable to HTTP request smuggling and HTTP response splitting attacks, caused by insuffic...
CVE-2026-54102Rejected reason: Reserved but no longer needed.
CVE-2026-54101Rejected reason: Reserved but no longer needed.
CVE-2026-49993MEDIUM5.7Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from vers...
CVE-2026-47200MEDIUM5.3Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1 ...
CVE-2026-46342MEDIUM5.4Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.1.0 to before 3.21.6 and 4.0.0-alpha.1 t...
CVE-2026-45670MEDIUM5.4Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder versions ...
CVE-2026-45669MEDIUM5.4Nuxt is an open-source web development framework for Vue.js. From versions 3.4.3 to before 3.21.6 and 4.0.0-alpha.1 to b...
CVE-2026-1836MEDIUM5.3The system stores the username and password from the login form after submitting the request. This could allow an attack...
CVE-2026-12066HIGH7.3A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the fi...
CVE-2026-12065LOW1.8A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown ...