CVE Vulnerability Database

Search and browse 377,880 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-63248MEDIUM6.5In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An an...
CVE-2026-62927HIGH7.5In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space hand...
CVE-2026-61387HIGH7.5In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fa...
CVE-2026-60007HIGH7.4In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA P...
CVE-2026-58080HIGH8.2In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On...
CVE-2026-18809MEDIUM6.5Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153...
CVE-2026-18806HIGH7.1External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-im...
CVE-2026-10710HIGH7.8A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerab...
CVE-2026-10709HIGH7.8A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerab...
CVE-2026-66884LOW2.1Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback mod...
CVE-2026-66883MEDIUM6.3Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize modu...
CVE-2026-10050CRITICAL9.1In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. Th...
CVE-2026-18772MEDIUM6.5Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data ...
CVE-2026-15721CRITICAL9.8Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Dig...
CVE-2026-14838HIGH7.4Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. ...
CVE-2026-14804CRITICAL9.1Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Hu...
CVE-2026-14465MEDIUM6.5Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human ...
CVE-2026-14219MEDIUM5.4URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUM...
CVE-2026-14202MEDIUM5.3Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human ...
CVE-2026-14194MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Infor...
CVE-2026-14192MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and...
CVE-2026-14175CRITICAL9.8Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIS...
CVE-2026-67243HIGH8.6freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the hig...
CVE-2026-18759HIGH8.5The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication...
CVE-2026-18755HIGH7.3A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search di...