CVE Vulnerability Database

Search and browse 377,822 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-69098CRITICAL9.8kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows ...
CVE-2026-25292HIGH7.6Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration...
CVE-2026-25289CRITICAL9.6Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with inv...
CVE-2026-25288HIGH7.4Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
CVE-2026-24084HIGH7.5Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed cap...
CVE-2026-24083HIGH7.8Memory Corruption while processing IOCTL device driver requests with invalid arguments.
CVE-2026-24080HIGH7.8Memory Corruption when handling malformed request parameters in the fingerprint TA.
CVE-2026-24079HIGH8.1Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
CVE-2026-24078MEDIUM6.5Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
CVE-2026-24077MEDIUM6.5Information Disclosure when processing wireless network channel switch information with improperly formatted length fiel...
CVE-2026-24076MEDIUM6.7Memory Corruption when processing registry values with incorrect types using a direct query method.
CVE-2026-21366HIGH7.8Memory corruption while processing a packet with a size close to the maximum allowed value.
CVE-2026-18801CRITICAL9.3OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution ...
CVE-2026-18773MEDIUM6.3A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_...
CVE-2026-10032MEDIUM6.1The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the U...
CVE-2026-69251CRITICAL9Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record ...
CVE-2026-69250HIGH8.5Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 toke...
CVE-2026-68494HIGH8.7The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint byp...
CVE-2026-67618MEDIUM6.5marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operat...
CVE-2026-67200HIGH8.7Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary...
CVE-2026-67199HIGH7.1Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop...
CVE-2026-67198HIGH8.7Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauth...
CVE-2026-67196MEDIUM5.4Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to in...
CVE-2026-67195HIGH8.8Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitr...
CVE-2026-61515CRITICAL9.8Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allo...