CVE Vulnerability Database

Search and browse 384,808 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-65703HIGH8.5FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows rem...
CVE-2026-64785MEDIUM5.3SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters r...
CVE-2026-63359CRITICAL9.8The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated att...
CVE-2026-60122HIGH8.5gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility tha...
CVE-2026-48013MEDIUM4.1Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint ...
CVE-2026-48012MEDIUM4.3Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO ...
CVE-2026-47722HIGH8.7nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `inter...
CVE-2026-47670CRITICAL9.4DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Executio...
CVE-2026-47669CRITICAL9.3DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api...
CVE-2026-25800HIGH7.5Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and...
CVE-2026-15212HIGH8.8The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43...
CVE-2026-12353MEDIUM5.3An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly se...
CVE-2026-65010MEDIUM6.6Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that a...
CVE-2026-63765HIGH8.8Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unau...
CVE-2026-16756HIGH8.7Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path o...
CVE-2026-15687LOW2.4A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new ...
CVE-2026-6516CRITICAL10Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the...
CVE-2026-65920MEDIUM5.3Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_...
CVE-2026-65919HIGH8.7Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api...
CVE-2026-65918HIGH7.1PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GI...
CVE-2026-65763MEDIUM5.1Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs...
CVE-2026-65762MEDIUM5.1Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user i...
CVE-2026-65702HIGH8.6Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration t...
CVE-2026-65701CRITICAL9.3SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inf...
CVE-2026-65700CRITICAL9.8h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthentica...