CVE Vulnerability Database

Search and browse 398,150 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-31984MEDIUM5.4HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Ty...
CVE-2025-31983MEDIUM4.6HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header. This cou...
CVE-2025-31982MEDIUM6.5HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed direct...
CVE-2025-31978MEDIUM4.3HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) befo...
CVE-2025-31976HIGH7.5HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while comm...
CVE-2025-31975MEDIUM5.3HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Expose...
CVE-2025-31959LOW3.5HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to co...
CVE-2025-31957MEDIUM5.7HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead t...
CVE-2026-36358MEDIUM5.4Cross Site Scripting vulnerability in Juzaweb CMS v.5.0.0 allows a remote attacker via execute arbitrary code via a craf...
CVE-2026-8026MEDIUM5.3A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packag...
CVE-2026-5081CRITICAL9.1Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure. Apache::Sessi...
CVE-2026-40562HIGH7.5Gazelle versions through 0.49 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Gazelle incorrectl...
CVE-2026-6210HIGH8.7A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. Wh...
CVE-2026-43283HIGH8.8In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ec_bhf: Fix dma_free_coherent() dma ...
CVE-2026-43282MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: RDMA/ionic: Fix potential NULL pointer dereference ...
CVE-2026-43281HIGH7.1In the Linux kernel, the following vulnerability has been resolved: mailbox: Prevent out-of-bounds access in fw_mbox_in...
CVE-2026-43280HIGH7.1In the Linux kernel, the following vulnerability has been resolved: drm/xe: Add bounds check on pat_index to prevent OO...
CVE-2026-43279HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Add sanity check for OOB writes at...
CVE-2026-43278HIGH7.8In the Linux kernel, the following vulnerability has been resolved: dm: clear cloned request bio pointer when last clon...
CVE-2026-43277MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: APEI/GHES: ensure that won't go past CPER allocated...
CVE-2026-43276HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix double destroy_workqueue on service ...
CVE-2026-43275MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Flush exception handling work when...
CVE-2026-43274HIGH8.4In the Linux kernel, the following vulnerability has been resolved: mailbox: mchp-ipc-sbi: fix out-of-bounds access in ...
CVE-2026-43273MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ceph: supply snapshot context in ceph_zero_partial_...
CVE-2026-43272MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix possible dereference of uninitiali...