CVE Vulnerability Database

Search and browse 384,069 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-60135HIGH7.1An attacker can modify data that should be restricted to read‑only access.
CVE-2026-60134HIGH8.8Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
CVE-2026-16280CRITICAL9.8An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computa...
CVE-2026-61884CRITICAL9.8The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credential...
CVE-2026-55985MEDIUM5.3The web management interface in  Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext o...
CVE-2025-71408HIGH8.5NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations m...
CVE-2026-66041HIGH7.8FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc fil...
CVE-2026-66040HIGH8.8FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and A...
CVE-2026-66039HIGH7.8FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decod...
CVE-2026-66038MEDIUM6.5FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video de...
CVE-2026-66037MEDIUM5.5FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF d...
CVE-2026-66036HIGH8.8FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter...
CVE-2026-62835HIGH7.5Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
CVE-2026-57531MEDIUM5.4Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allo...
CVE-2026-57530MEDIUM5.4Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milk...
CVE-2026-54342HIGH8.1In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensyste...
CVE-2026-48037MEDIUM6.3Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P...
CVE-2026-48036HIGH8.4Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P...
CVE-2026-48035HIGH7.1Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P...
CVE-2026-48034HIGH8.5Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P...
CVE-2026-48033HIGH8.4Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P...
CVE-2026-48032HIGH8.3Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P...
CVE-2026-48021CRITICAL9.1In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA ba...
CVE-2026-17107HIGH8.5A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes...
CVE-2026-66035HIGH7.7libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that a...