CVE Vulnerability Database

Search and browse 388,339 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-40714HIGH7.2Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A hig...
CVE-2026-40712HIGH7.2Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the...
CVE-2026-16607HIGH8.5A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allow...
CVE-2026-16606CRITICAL9.8A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allow...
CVE-2026-16552Rejected reason: The reported issue is invalid, as it requires root privileges to reproduce, and it is out of scope of t...
CVE-2026-48029HIGH7.1libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in Image...
CVE-2026-2395CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Info...
CVE-2026-14985HIGH7.8The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the ...
CVE-2026-13321HIGH8.6The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zon...
CVE-2026-13204HIGH7.5If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for on...
CVE-2026-12617HIGH7.5The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME ...
CVE-2026-11721HIGH7.5It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the z...
CVE-2026-11622HIGH7.5A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runawa...
CVE-2026-11605HIGH7.5The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG reco...
CVE-2026-11331HIGH7.5An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enou...
CVE-2026-10822MEDIUM6.5If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequ...
CVE-2026-10723MEDIUM6.8BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMA...
CVE-2026-62145HIGH7.5A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to exe...
CVE-2026-62144CRITICAL9.1An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an...
CVE-2026-56444MEDIUM5.9In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve...
CVE-2026-56416MEDIUM4.8In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSI...
CVE-2026-55991MEDIUM5.9In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 asserti...
CVE-2026-55990MEDIUM5.9In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:'...
CVE-2026-55973HIGH7.5In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel...
CVE-2026-55717MEDIUM5.9In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: ...