CVE Vulnerability Database

Search and browse 381,178 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-67318MEDIUM6.3axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bo...
CVE-2026-67317MEDIUM6.3axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch a...
CVE-2026-67316MEDIUM6.3axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype h...
CVE-2026-67315MEDIUM6.9axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBy...
CVE-2026-67314MEDIUM6.3axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/a...
CVE-2026-67313MEDIUM6.3axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names wi...
CVE-2026-67312MEDIUM6.3axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (...
CVE-2026-67311HIGH8.2Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fail...
CVE-2026-67310MEDIUM5.4OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in t...
CVE-2026-67309HIGH7.8Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider...
CVE-2026-67308CRITICAL9.3Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execut...
CVE-2026-67307HIGH7Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inven...
CVE-2026-67306MEDIUM5.4FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder fu...
CVE-2026-67305CRITICAL9.4FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when...
CVE-2026-67304HIGH8.7FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when...
CVE-2026-67303MEDIUM5.3FreeRDP before 3.29.0 contains a reachable assertion (WINPR_ASSERT(OutputBufferLength == BytesReturned)) in serial_proce...
CVE-2026-67302MEDIUM5.3FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a divide-by-zero vulnerability in the rdpecam camera redire...
CVE-2026-67301HIGH8.7FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC an...
CVE-2026-67300HIGH8.7FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAI...
CVE-2026-67299HIGH8.7FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER...
CVE-2026-67298HIGH8.7FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_...
CVE-2026-67297HIGH8.7FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses...
CVE-2026-67296HIGH8.7FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to valid...
CVE-2026-67295MEDIUM6.3FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to...
CVE-2026-67294CRITICAL9.3FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-si...