CVE Vulnerability Database

Search and browse 375,854 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-20712MEDIUM4Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disc...
CVE-2026-0465MEDIUM5.6A Use‑After‑Free (UAF) vulnerability in the AMD Ryzen™ Master Utility Driver could allow a local attacker to access kern...
CVE-2025-54512HIGH7A DLL hijacking vulnerability within the AMD Ryzen Master installation could allow a local user-privileged attacker to e...
CVE-2025-0046HIGH7Incorrect directory permissions could allow a local user to escalate their privileges, potentially resulting in arbitrar...
CVE-2022-50997HIGH7.5Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint th...
CVE-2016-20097HIGH7.5Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthe...
CVE-2026-73089HIGH7.5Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to ...
CVE-2026-73088HIGH7.5Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to ...
CVE-2026-73087LOW2.3Dozzle is a realtime log viewer for docker containers. From 10.5.2 until 10.6.15, the isBlockedIP SSRF guard in internal...
CVE-2026-73086HIGH7.4nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the na...
CVE-2026-73085MEDIUM5.3Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.36.0, the jwtAuthCheck function in server/auth/...
CVE-2026-73084MEDIUM6.1Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoi...
CVE-2026-73083HIGH7.6Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, in SANDBOX_CODE_ONLY mode, the engine l...
CVE-2026-73082MEDIUM5.3Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mc...
CVE-2026-73081HIGH8.7Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, the worker's code-compilation pipeline ...
CVE-2026-72971MEDIUM5.5Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs....
CVE-2026-71390MEDIUM4CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur...
CVE-2026-71389MEDIUM6.2CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a...
CVE-2026-71387HIGH8.8ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the ...
CVE-2026-71386HIGH8.8is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context o...
CVE-2026-71384CRITICAL9.6is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker coul...
CVE-2026-71383HIGH7.3is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker coul...
CVE-2026-71331HIGH8.1Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an un...
CVE-2026-70355HIGH7.3Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-70354HIGH7.8Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.