CVE Vulnerability Database

Search and browse 396,204 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-49959HIGH8.8Hermes WebUI before version 0.51.311 contains a remote code execution vulnerability that allows authenticated attackers ...
CVE-2026-49958MEDIUM5Hermes WebUI before version 0.51.303 contains a time-of-check time-of-use (TOCTOU) race condition vulnerability in the g...
CVE-2026-49957HIGH7.7Hermes WebUI before version 0.51.296 contains a workspace boundary bypass vulnerability that allows authenticated attack...
CVE-2026-49956HIGH7.1Hermes WebUI before version 0.51.269 contains a profile isolation bypass vulnerability that allows authenticated users t...
CVE-2026-49955MEDIUM6.9Hermes WebUI before version 0.51.270 contains a resource exhaustion vulnerability that allows unauthenticated remote att...
CVE-2026-49848MEDIUM4.3FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2026-49847HIGH7.5FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2026-49843MEDIUM5.3FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2026-49842HIGH7.5FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2026-49841CRITICAL9.8FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2026-49840CRITICAL9.1FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2026-49475HIGH7.5FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2026-49472MEDIUM5.3FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2026-49161HIGH7.8Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.
CVE-2026-49160HIGH7.5Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.
CVE-2026-48583HIGH7.8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-48578HIGH7.9Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.
CVE-2026-48576HIGH7.9No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-48575HIGH7.9Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-48574HIGH7.8Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
CVE-2026-48573HIGH7.9No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-48570HIGH7.9Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-48569MEDIUM5.5Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-48568HIGH7.9Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-48566MEDIUM5.5Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.