CVE Vulnerability Database

Search and browse 380,666 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-64577HIGH7.5In the Linux kernel, the following vulnerability has been resolved: gtp: check skb_pull_data() return in gtp1u_send_ech...
CVE-2026-64576HIGH7.1In the Linux kernel, the following vulnerability has been resolved: nexthop: initialize extack in nh_res_bucket_migrate...
CVE-2026-64575HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: tcp: fix double sock release on batch realloc ...
CVE-2026-64574HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: tear down new links on vif update e...
CVE-2026-64573In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix NVM tag length underflow in TLV...
CVE-2026-64572In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: free fib_alias with kfree_rcu() on inser...
CVE-2026-64571In the Linux kernel, the following vulnerability has been resolved: wifi: p54: validate RX frame length in p54_rx_eepro...
CVE-2026-64570HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix fils_discovery double free on a...
CVE-2026-64569In the Linux kernel, the following vulnerability has been resolved: mpls: fix NULL deref in mpls_valid_fib_dump_req() o...
CVE-2026-64568HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix unsol_bcast_probe_resp double f...
CVE-2026-64567HIGH7.8In the Linux kernel, the following vulnerability has been resolved: btrfs: reject free space cache with more entries th...
CVE-2026-64566CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_s...
CVE-2026-61486CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Luc...
CVE-2026-61485HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue af...
CVE-2026-61484CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apac...
CVE-2026-61483HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: al...
CVE-2026-5651MEDIUM4.9The Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in multiple AJAX actions (a...
CVE-2026-5581CRITICAL9.1The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all ...
CVE-2026-5116MEDIUM4.4The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ver...
CVE-2026-5108MEDIUM4.4The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_setti...
CVE-2026-59675HIGH7.5When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a siz...
CVE-2026-55998MEDIUM5.3The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid ...
CVE-2026-55997HIGH8.8Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These token...
CVE-2026-55996MEDIUM4.3A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent com...
CVE-2026-55747MEDIUM6.8The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir...