CVE Vulnerability Database

Search and browse 397,974 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-0243MEDIUM6.5A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attac...
CVE-2026-8496MEDIUM6.1A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar in...
CVE-2026-8466HIGH8.2Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows denial of service via unbo...
CVE-2026-44248HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT ...
CVE-2026-43970HIGH8.2Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in ninenines cowlib allows unauthenticate...
CVE-2026-42587HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpConte...
CVE-2026-42586HIGH7.1Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty...
CVE-2026-42585HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty inc...
CVE-2026-42584CRITICAL9.1Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClien...
CVE-2026-42583HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameD...
CVE-2026-42582HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks...
CVE-2026-42581CRITICAL9.8Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjec...
CVE-2026-42580MEDIUM6.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's c...
CVE-2026-42579CRITICAL9.1Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's D...
CVE-2026-42578HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's H...
CVE-2026-42577HIGH7.5Netty is an asynchronous, event-driven network application framework. From 4.2.0.Final to 4.2.13.Final , Netty's epoll t...
CVE-2026-42032CRITICAL9.1CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5...
CVE-2026-42031CRITICAL9.8CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5...
CVE-2026-41410——Rejected reason: REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-40520. Reason: This candidate is a dup...
CVE-2026-41255MEDIUM6.1CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5...
CVE-2026-41132HIGH7.4CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5...
CVE-2026-33585LOW3.8Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacke...
CVE-2026-33584MEDIUM5.3Exposed Keycloak management service in the Arqit Symmetric Key Agreement Platform enables unauthorized access to sensit...
CVE-2026-33583HIGH8.7Exposure of the QKEY (used as input into the ‘OTA-Quantum’ device registration process) and internal system keys via a...
CVE-2026-30906HIGH7.8Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user t...