CVE Vulnerability Database

Search and browse 396,279 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-40376HIGH8.1Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-40371HIGH8.8Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized...
CVE-2026-3088MEDIUM6.5Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted reque...
CVE-2026-38615CRITICAL9.8DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
CVE-2026-35188MEDIUM5Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_requ...
CVE-2026-34692MEDIUM5.4Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting ...
CVE-2026-34335HIGH7Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca...
CVE-2026-34183HIGH7.5Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing P...
CVE-2026-34182CRITICAL9.1Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the ciphe...
CVE-2026-34181HIGH7.4Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Base...
CVE-2026-34180HIGH7.5Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes ...
CVE-2026-33828HIGH7.8Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.
CVE-2026-33113MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-32193HIGH8.8Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service all...
CVE-2026-28301MEDIUM4.8A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended websit...
CVE-2026-26142CRITICAL9.8Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.
CVE-2026-24181HIGH7.3NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A succes...
CVE-2026-24180HIGH7.3NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A succes...
CVE-2026-22926HIGH7.8Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.
CVE-2026-0420MEDIUM5.9An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which co...
CVE-2026-0419HIGH8Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows u...
CVE-2026-0418MEDIUM4.5Insufficient configuration management in the listed devices allows authenticated administrators connected to the local n...
CVE-2026-0417MEDIUM4.5Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected ...
CVE-2026-0416MEDIUM4.5An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated admini...
CVE-2026-0415MEDIUM4.5Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t...