CVE Vulnerability Database

Search and browse 383,919 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-64649MEDIUM6.5Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 thr...
CVE-2026-64648MEDIUM5.4Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-59729MEDIUM5.1Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped sp...
CVE-2026-59727LOW2.1Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a transition:persist, trans...
CVE-2026-56748HIGH8.8Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authe...
CVE-2026-56747HIGH8.8Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a r...
CVE-2026-42017HIGH8.8An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged use...
CVE-2026-42016HIGH8.8JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a valida...
CVE-2026-66759HIGH7.1A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the pl...
CVE-2026-66758HIGH7.8A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory alloca...
CVE-2026-66757MEDIUM5.5A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memor...
CVE-2026-66031MEDIUM5.4Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent...
CVE-2026-64647MEDIUM5.4Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-64646MEDIUM5.3Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-51244Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-17612MEDIUM6.9Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains...
CVE-2026-16481HIGH8.4A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch...
CVE-2026-12383HIGH7.5A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access control...
CVE-2026-10683MEDIUM4.6In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating in target/slave mode, the rx_full interrupt handl...
CVE-2026-10682HIGH7.8The userspace verifier z_vrfy_log_filter_set() for the log_filter_set syscall in subsys/logging/log_mgmt.c performed a s...
CVE-2026-66030MEDIUM5.4Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authen...
CVE-2026-66029MEDIUM5.4Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent...
CVE-2026-66028HIGH7.1Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authe...
CVE-2026-64645MEDIUM6.1Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-64644MEDIUM5.3Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 thr...