CVE Vulnerability Database

Search and browse 383,916 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-28932MEDIUM5.5A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is f...
CVE-2026-28931HIGH8.8A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Ta...
CVE-2026-28928CRITICAL9.8A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, m...
CVE-2026-28926HIGH7A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 1...
CVE-2026-28912HIGH7.8A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.7...
CVE-2026-28911CRITICAL9.8The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A m...
CVE-2026-28900MEDIUM5.5A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma...
CVE-2026-28896HIGH7.7The issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15...
CVE-2026-28849MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Ta...
CVE-2026-20672MEDIUM5.5An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7....
CVE-2026-12001MEDIUM5.2A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-...
CVE-2026-66018MEDIUM6.5Build readers can access another repository's environment properties. A caller with read access to an ordinary repositor...
CVE-2026-66015HIGH7.2An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account c...
CVE-2026-66014CRITICAL9.8JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific condi...
CVE-2026-65925MEDIUM6.5A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and ret...
CVE-2026-65924MEDIUM6.5JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (...
CVE-2026-65923MEDIUM6.8A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository...
CVE-2026-65922MEDIUM5.4An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository acc...
CVE-2026-65921HIGH8.8A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written ou...
CVE-2026-65618MEDIUM6.5Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized ...
CVE-2026-65617HIGH8.8A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentia...
CVE-2026-65616HIGH8.8Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administra...
CVE-2026-64649MEDIUM6.5Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 thr...
CVE-2026-64648MEDIUM5.4Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-59729MEDIUM5.1Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped sp...