CVE Vulnerability Database

Search and browse 381,619 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-60113CRITICAL9.8AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnera...
CVE-2026-60112CRITICAL9.8AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthen...
CVE-2026-54735CRITICAL10Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0...
CVE-2026-54082MEDIUM6.5veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, ve...
CVE-2026-54081MEDIUM6.9veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service...
CVE-2026-54080MEDIUM6.9veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service...
CVE-2026-54079HIGH8.7veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30...
CVE-2026-54078HIGH8.7veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, ve...
CVE-2026-50558MEDIUM5.9Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix d...
CVE-2026-17550MEDIUM5.5A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerabili...
CVE-2026-16543HIGH7.1Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation pr...
CVE-2026-16465HIGH7.1A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerabili...
CVE-2026-16463HIGH7.8A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A m...
CVE-2026-15228HIGH7.1Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a clust...
CVE-2026-66724MEDIUM5.3MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob u...
CVE-2026-66723HIGH7MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. ...
CVE-2026-65947HIGH7.3Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2
CVE-2026-65888CRITICAL9.8Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows acto...
CVE-2026-65887CRITICAL9.8Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method...
CVE-2026-65886HIGH7.5Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unaut...
CVE-2026-59247HIGH7.6Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute fo...
CVE-2026-54666HIGH8.3swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/sch...
CVE-2026-54664HIGH8.3swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/sch...
CVE-2026-54663MEDIUM6.1swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol...
CVE-2026-54662HIGH8.3swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-...