CVE Vulnerability Database
Search and browse 378,059 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58042 | MEDIUM | 5.9 | — | Aug 4, 2026 | A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Rec... |
| CVE-2026-58041 | MEDIUM | 5.3 | — | Aug 4, 2026 | A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to cont... |
| CVE-2026-56846 | HIGH | 7.5 | — | Aug 4, 2026 | A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memor... |
| CVE-2026-56845 | HIGH | 7.5 | — | Aug 4, 2026 | An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configur... |
| CVE-2026-66326 | HIGH | 8.8 | 0.7% | Aug 4, 2026 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-66325 | MEDIUM | 6.1 | 0.4% | Aug 4, 2026 | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofin... |
| CVE-2026-66322 | MEDIUM | 5.4 | 0.3% | Aug 4, 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne... |
| CVE-2026-66321 | CRITICAL | 9.6 | 0.9% | Aug 4, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ... |
| CVE-2026-66318 | HIGH | 8.1 | 0.4% | Aug 4, 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over ... |
| CVE-2026-66317 | MEDIUM | 5.4 | 0.2% | Aug 4, 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a n... |
| CVE-2026-66316 | MEDIUM | 5.4 | 0.2% | Aug 4, 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne... |
| CVE-2026-66315 | HIGH | 7.5 | 0.6% | Aug 4, 2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-66314 | MEDIUM | 5.3 | 0.7% | Aug 4, 2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to ... |
| CVE-2026-66313 | MEDIUM | 6.8 | 0.2% | Aug 4, 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. |
| CVE-2026-66312 | HIGH | 8.8 | 1.0% | Aug 4, 2026 | Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. |
| CVE-2026-66311 | MEDIUM | 6.2 | 0.4% | Aug 4, 2026 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. |
| CVE-2026-66310 | HIGH | 7.1 | 0.4% | Aug 4, 2026 | External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat... |
| CVE-2026-65804 | MEDIUM | 6.1 | 0.4% | Aug 4, 2026 | Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized atta... |
| CVE-2026-65802 | HIGH | 7.4 | 0.9% | Aug 4, 2026 | External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat... |
| CVE-2026-62870 | HIGH | 8.8 | 0.8% | Aug 4, 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. |
| CVE-2026-18686 | CRITICAL | 9.8 | 2.6% | Aug 4, 2026 | A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of ... |
| CVE-2026-18685 | CRITICAL | 9.8 | 2.0% | Aug 4, 2026 | A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the... |
| CVE-2026-11836 | LOW | 1.8 | 0.1% | Aug 4, 2026 | Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in... |
| CVE-2026-11835 | MEDIUM | 5.6 | 0.1% | Aug 4, 2026 | Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateRese... |
| CVE-2026-67978 | HIGH | 7.5 | 0.1% | Aug 3, 2026 | An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmittin... |
