CVE Vulnerability Database

Search and browse 380,994 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-15055MEDIUM5.3In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also a...
CVE-2026-12185HIGH7.1In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This i...
CVE-2026-3245HIGH7.7A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.
CVE-2026-18577HIGH8.1An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions throu...
CVE-2026-10848HIGH8.6The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j...
CVE-2026-9856HIGH7.1A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes vi...
CVE-2026-65321CRITICAL9.8PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrar...
CVE-2026-10774MEDIUM6.5Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/blue...
CVE-2026-68583MEDIUM5.4luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field th...
CVE-2026-68582CRITICAL9.3Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-col...
CVE-2026-68581HIGH8.6Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and ...
CVE-2026-68580HIGH7.7FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across AL...
CVE-2026-68579CRITICAL9.6FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_...
CVE-2026-68578HIGH7.7ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine p...
CVE-2026-67357HIGH7.7ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that...
CVE-2026-67356HIGH8.8ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowin...
CVE-2025-71401CRITICAL9.3better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., B...
CVE-2025-71400HIGH7.1better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey delet...
CVE-2025-71399HIGH8.8Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalize...
CVE-2026-12231MEDIUM6.4The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_info...
CVE-2026-18573MEDIUM6.5A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authoriza...
CVE-2026-18572MEDIUM6.5Keycloak provides authorization services that allow administrators to restrict access to resources based on time policie...
CVE-2026-18571HIGH7.2A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled....
CVE-2026-18570MEDIUM5.4A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This componen...
CVE-2026-16540HIGH7.5The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operati...