CVE Vulnerability Database

Search and browse 398,082 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-6659HIGH7.5Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function ...
CVE-2026-42072CRITICAL9.8Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and wri...
CVE-2026-42030MEDIUM6.1MapServer is a system for developing web-based GIS applications. From version 6.0 to before version 8.6.2, a reflected X...
CVE-2026-42028MEDIUM5.3novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGa...
CVE-2026-41889CRITICAL9.8pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simp...
CVE-2026-41887MEDIUM4.9Flarum is open-source forum software. Prior to versions 1.8.16 and 2.0.0-rc.1, Flarum's patch for CVE-2023-27577 restric...
CVE-2026-38360CRITICAL9.8Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execut...
CVE-2026-44499HIGH8.7ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Z...
CVE-2026-43967HIGH7.5Inefficient Algorithmic Complexity vulnerability in absinthe-graphql absinthe allows unauthenticated denial of service v...
CVE-2026-42794MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in absinthe-graphql absinthe_plug allows...
CVE-2026-42793HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in absinthe-graphql absinthe allows unauthenticated d...
CVE-2026-42353HIGH8.2i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno...
CVE-2026-41886HIGH7.5locize is a localization platform that connects code and i18n setup. Prior to version 4.0.21, the locize client SDK regi...
CVE-2026-41885MEDIUM6.5i18next-locize-backend is a simple i18next backend for locize.com which can be used in Node.js, in the browser and for D...
CVE-2026-41883HIGH8.1OmniFaces is a utility library for Faces. Prior to versions 1.14.2, 2.7.32, 3.14.16, 4.7.5, and 5.2.3, there is a server...
CVE-2026-41693HIGH8.2i18next-fs-backend is a backend layer for i18next using in Node.js and for Deno to load translations from the filesystem...
CVE-2026-41690HIGH8.618next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno....
CVE-2026-41683HIGH8.6i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno...
CVE-2026-41591MEDIUM6.4Marko is a declarative, HTML-based language for building web apps. Prior to marko version 5.38.36 and prior to @marko/ru...
CVE-2026-41070CRITICAL10openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (S...
CVE-2026-34354HIGH7.4Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escal...
CVE-2026-29975HIGH7.5lwjson 1.8.1 contains an improper input validation vulnerability in the streaming JSON parser (lwjson_stream.c). The end...
CVE-2026-29974HIGH7.5An issue was discovered in kosma minmea 0.3.0. The minmea_scan functions format specifier copies NMEA field data to a ca...
CVE-2026-29972HIGH8.2nanoMODBUS through v1.22.0 has a stack-based buffer overflow in recv_read_registers_res() in nanomodbus.c. When a client...
CVE-2026-44500MEDIUM5.3ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and p...