CVE Vulnerability Database

Search and browse 397,676 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-9749HIGH7.1This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-ran...
CVE-2026-9748HIGH7.1The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index st...
CVE-2026-9747HIGH7.1Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.
CVE-2026-9746HIGH7.1When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which...
CVE-2026-9743HIGH7.1In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines...
CVE-2026-9742MEDIUM5.9When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of th...
CVE-2026-9741HIGH7.1A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side F...
CVE-2026-9740HIGH8.7A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by ...
CVE-2026-9735MEDIUM6.8MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. W...
CVE-2026-46433MEDIUM6.5lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips ...
CVE-2026-46374HIGH7.5SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to vers...
CVE-2026-46373HIGH7.5SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to vers...
CVE-2026-44963CRITICAL9.4A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
CVE-2026-10238——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-47905MEDIUM6.2CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu...
CVE-2026-47904MEDIUM6.2CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu...
CVE-2026-47903MEDIUM6.2CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation v...
CVE-2026-47902MEDIUM6.2CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu...
CVE-2026-34713HIGH7.5CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu...
CVE-2026-34712HIGH7.5CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation v...
CVE-2026-34711HIGH7.5CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Integer Overflow or Wraparo...
CVE-2026-34657MEDIUM5.5CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pa...
CVE-2026-34417MEDIUM6.1OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbit...
CVE-2026-25860MEDIUM6.1OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that al...
CVE-2026-48303CRITICAL10Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerabil...