CVE Vulnerability Database

Search and browse 397,532 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-2049HIGH7.8GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2026-11604MEDIUM6.5An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allo...
CVE-2026-10143HIGH7.5kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a ma...
CVE-2026-10142HIGH8.7kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious br...
CVE-2026-0274CRITICAL9.1An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex X...
CVE-2026-0273HIGH7.2A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypas...
CVE-2026-0272HIGH7.2A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with a...
CVE-2026-0271HIGH7.8A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a l...
CVE-2026-0270HIGH7.5A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenti...
CVE-2026-0269MEDIUM5.7A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an a...
CVE-2026-0268MEDIUM4.4A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffi...
CVE-2026-0267MEDIUM5.5An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn...
CVE-2026-0266MEDIUM4.8A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated admi...
CVE-2022-48575LOW3.5A person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed with improved state ...
CVE-2022-26758HIGH7.1A malicious application may cause unexpected changes in memory shared between processes. A memory corruption issue was a...
CVE-2026-6893HIGH7.5A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specia...
CVE-2026-50127MEDIUM5.9Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did...
CVE-2026-46683MEDIUM6.9Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.0...
CVE-2026-46643HIGH7.5Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.1...
CVE-2026-46529HIGH8.4Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote co...
CVE-2026-45106MEDIUM4.6Weblate is a web based localization tool. Prior to version 2026.5, Weblate's live search preview renders unit source and...
CVE-2026-1220HIGH7.5Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a...
CVE-2026-50639MEDIUM6.5Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections. The statsd pr...
CVE-2026-50638CRITICAL9.1Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd p...
CVE-2026-50637HIGH8.2Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections. The statsd prot...