CVE Vulnerability Database

Search and browse 397,870 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-3660CRITICAL9.8IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update se...
CVE-2026-3603HIGH7.1IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Int...
CVE-2026-9567LOW3.3A security flaw has been discovered in GPAC up to 2.4.0. Affected is the function MergeFragment of the file src/isomedia...
CVE-2026-9566MEDIUM4.3A vulnerability was identified in teableio teable up to 1.9.x. This impacts an unknown function of the file apps/nextjs-...
CVE-2026-9560HIGH7.8Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute ...
CVE-2026-9170CRITICAL9.8IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper in...
CVE-2026-8856CRITICAL9.1IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to ...
CVE-2026-8855CRITICAL9.8IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mut...
CVE-2026-8854HIGH7.5IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.
CVE-2026-8835HIGH7.3IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Admin...
CVE-2026-8834HIGH8IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administr...
CVE-2026-8633CRITICAL9.8IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server...
CVE-2026-8620HIGH7.5IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server...
CVE-2026-7454HIGH7.8A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A mal...
CVE-2026-7453MEDIUM5.5A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion vulnerability, leadin...
CVE-2026-7452HIGH7.8A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A mal...
CVE-2026-7451HIGH7.8A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A ...
CVE-2026-7450MEDIUM5.5A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Dereference vulnerability...
CVE-2026-7251CRITICAL9.8Eppendorf BioFlo 320 is vulnerable due to VNC server using a hard-coded password. If a remote attacker knows the network...
CVE-2026-48696MEDIUM6.2FastNetMon Community Edition through 1.2.9 has a buffer overflow, a different vulnerability than CVE-2026-48686 and CVE-...
CVE-2026-48695HIGH8.1FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integra...
CVE-2026-48694HIGH8.1FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integr...
CVE-2026-47202CRITICAL9.3Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unau...
CVE-2026-46624CRITICAL9.9Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in ...
CVE-2026-44776MEDIUM5.9Kavita is a cross platform reading server. Prior to 0.9.0, the download, size-check, and chapter metadata endpoints do n...