CVE Vulnerability Database

Search and browse 378,075 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-20475MEDIUM6In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o...
CVE-2026-20474MEDIUM6In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of ...
CVE-2026-20473MEDIUM6In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg...
CVE-2026-20472MEDIUM4.4In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of servic...
CVE-2026-20471MEDIUM4.6In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service...
CVE-2026-20470MEDIUM6.2In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local inf...
CVE-2026-20469MEDIUM6In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local e...
CVE-2026-20468MEDIUM6In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of ...
CVE-2026-20467MEDIUM6In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalatio...
CVE-2026-20466MEDIUM6.1In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalat...
CVE-2026-20465HIGH8.1In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (pro...
CVE-2026-20464MEDIUM6.5In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalatio...
CVE-2026-18582MEDIUM5.5A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1. This vulnerability affects the function Re...
CVE-2026-8763CRITICAL9.3In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also a...
CVE-2026-65875HIGH7.1BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens...
CVE-2026-59652MEDIUM6.9In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
CVE-2026-59651HIGH7.1In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue als...
CVE-2026-59650CRITICAL9.3In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects...
CVE-2026-59649HIGH8.7In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issu...
CVE-2026-59648MEDIUM6.9In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also aff...
CVE-2026-59647MEDIUM6.9In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects ...
CVE-2026-59646HIGH8.7In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This is...
CVE-2026-59645HIGH8.7In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. T...
CVE-2026-59644HIGH8.7In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender.
CVE-2026-59643HIGH8.7In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affect...