CVE Vulnerability Database

Search and browse 383,853 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-51259Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51254Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51252Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51251Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-67173MEDIUM5.1Pivotick did not validate the URL scheme of node imagePath values derived from graph data before assigning them to SVG i...
CVE-2026-66922MEDIUM5.1Pivotick used plain JavaScript objects as lookup tables indexed by caller-controlled graph node identifiers in its tree-...
CVE-2026-66921MEDIUM6.3Pivotick’s Markdown node-reference renderer failed to HTML-escape the attacker-controlled nodeName value before interpol...
CVE-2026-61487MEDIUM6.5Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated...
CVE-2026-59878HIGH7.5Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthe...
CVE-2026-7187HIGH8.8Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionalit...
CVE-2026-66920HIGH8.2Pivotick contains an uncontrolled-recursion vulnerability when processing caller-supplied graph and node data. The affec...
CVE-2026-66919MEDIUM6.9Pivotick contains a cross-site scripting vulnerability in the inspect and edit node modals. Node labels and descriptions...
CVE-2026-66918HIGH8.2Pivotick fails to sanitize attacker-controlled SVG markup supplied through the per-node style.svgIcon property before in...
CVE-2026-66913MEDIUM6.9Lookyloo did not enforce limits on the decompressed size of uploaded capture archives and compressed HAR files. An atta...
CVE-2026-65882MEDIUM6.1Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1 - The goto url parameter of the moodle w...
CVE-2026-65881HIGH7.5Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1...
CVE-2026-62436MEDIUM6.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-62435MEDIUM6.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-62434MEDIUM5.3A guest started with Populated on Demand enabled (PoD) can attempt to reclaim pages which aren't regular guest RAM. Thi...
CVE-2026-62433HIGH7.3Parts of the DM_OP handling code assumes the caller has provided the required number of buffers for the given operation ...
CVE-2026-62432HIGH7.3The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without holding the correct ...
CVE-2026-62431HIGH7.5The logic to handle periodic Viridian STIMERs performs a division with an unchecked user-controlled divisor value, that ...
CVE-2026-62430HIGH7.5Accesses to the CMOS memory contents are done using an indirect IO port pair. Therefore Xen needs to cache the guest ch...
CVE-2026-62429MEDIUM6.5Accessing the vNUMA configuration data of a guest is still possible when domain destruction has already started. The cl...
CVE-2026-62428HIGH7.8When grant-copy operations are processed, the respective grant may or may not already be in use by another operation (a ...