CVE Vulnerability Database

Search and browse 397,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-2031CRITICAL10An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prio...
CVE-2026-8669MEDIUM6.5Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager:...
CVE-2026-46483HIGH7Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimu...
CVE-2026-45736HIGH7.5ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is v...
CVE-2026-39054HIGH7.3Oinone Pamirs 7.0.0 contains a command injection vulnerability in CommandHelper.executeCommands. The method starts a she...
CVE-2026-39053MEDIUM6.5Oinone Pamirs 7.0.0 contains an XML External Entity (XXE) issue in its XStream-based XML parsing logic. When attacker-co...
CVE-2026-39052MEDIUM6.5Oinone Pamirs 7.0.0 contains a code execution vulnerability via ScriptRunner. The method ScriptRunner.run(String express...
CVE-2026-38728HIGH7.5An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStr...
CVE-2026-34253HIGH8.2A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in functi...
CVE-2025-67437MEDIUM6.5Medical Management System a81df1ce700a9662cb136b27af47f4cbde64156b is vulnerable to Insecure Permissions, which allows a...
CVE-2025-14972MEDIUM4.1* Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices are not sufficiently random and will eventually...
CVE-2026-46333HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The ...
CVE-2026-7182CRITICAL9.2Diagram's export module is vulnerable to Path Traversal in src attribute due to lack of HTML sanitization. An unauthenti...
CVE-2026-41553CRITICAL10PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "d...
CVE-2026-41552HIGH7.5PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sani...
CVE-2026-8503MEDIUM6.5Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids. Apache::Session::Generat...
CVE-2026-8454MEDIUM5.3Imager::File::GIF versions through 1.002 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF file...
CVE-2026-41971MEDIUM5.5Permission control vulnerability in the security control module. Impact: Successful exploitation of this vulnerability m...
CVE-2026-41970MEDIUM6.8Out-of-bounds write vulnerability in the distributed file system module. Impact: Successful exploitation of this vulnera...
CVE-2026-41969MEDIUM6.2Permission control vulnerability in the projection module. Impact: Successful exploitation of this vulnerability may aff...
CVE-2026-41968MEDIUM5.9Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnera...
CVE-2026-41967MEDIUM5.9Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnera...
CVE-2026-41966MEDIUM5.6Permission control vulnerability in the smart sensing service. Impact: Successful exploitation of this vulnerability may...
CVE-2026-41965MEDIUM5.6Use-After-Free (UAF) vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availabi...
CVE-2026-41964HIGH8.4Permission control vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availabili...