CVE Vulnerability Database

Search and browse 397,696 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-34182CRITICAL9.1Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the ciphe...
CVE-2026-34181HIGH7.4Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Base...
CVE-2026-34180HIGH7.5Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes ...
CVE-2026-33828HIGH7.8Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.
CVE-2026-33113MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-32193HIGH8.8Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service all...
CVE-2026-28301MEDIUM4.8A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended websit...
CVE-2026-26142CRITICAL9.8Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.
CVE-2026-24181HIGH7.3NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A succes...
CVE-2026-24180HIGH7.3NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A succes...
CVE-2026-22926HIGH7.8Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.
CVE-2026-0420MEDIUM5.9An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which co...
CVE-2026-0419HIGH8Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows u...
CVE-2026-0418MEDIUM4.5Insufficient configuration management in the listed devices allows authenticated administrators connected to the local n...
CVE-2026-0417MEDIUM4.5Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected ...
CVE-2026-0416MEDIUM4.5An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated admini...
CVE-2026-0415MEDIUM4.5Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t...
CVE-2026-0414MEDIUM4.5Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t...
CVE-2026-0413MEDIUM4.5A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated a...
CVE-2026-0412MEDIUM4.5Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in ...
CVE-2026-0411HIGH8An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected...
CVE-2026-0410MEDIUM4.5Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorize...
CVE-2026-0409MEDIUM6.4A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the rout...
CVE-2026-8045MEDIUM6.5CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosu...
CVE-2026-8025CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information T...