CVE Vulnerability Database

Search and browse 383,942 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-56538LOW3.5An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosi...
CVE-2026-56537LOW3.5HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they ar...
CVE-2026-17512LOW3.3A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This impacts the function log_mel_spectrogram of the fi...
CVE-2026-12991HIGH8.7The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Visio...
CVE-2026-12990HIGH7.7An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simul...
CVE-2026-12989HIGH8.7A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated at...
CVE-2026-66053MEDIUM5.9Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affect...
CVE-2026-58662CRITICAL9.1Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. Thi...
CVE-2026-58389HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects A...
CVE-2026-58023CRITICAL9.1Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Us...
CVE-2026-57917MEDIUM4.8proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially a...
CVE-2026-57916MEDIUM4.6proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare ar...
CVE-2026-55971CRITICAL9.8Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0...
CVE-2026-55970MEDIUM6.5Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users a...
CVE-2026-55969HIGH7.5Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This i...
CVE-2026-55968HIGH7.5Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift ...
CVE-2026-49158HIGH7.5Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This iss...
CVE-2026-48586HIGH7.5Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D...
CVE-2026-48145HIGH7.5Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects A...
CVE-2026-48144CRITICAL9.1Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affect...
CVE-2026-45112HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects A...
CVE-2026-43871HIGH7.5Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings....
CVE-2026-41608HIGH7.5Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This i...
CVE-2026-14856MEDIUM6.3A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter ...
CVE-2026-12495MEDIUM5.3Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys M...