CVE Vulnerability Database

Search and browse 389,869 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-49092MEDIUM4.3Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure v...
CVE-2026-47671MEDIUM5.4Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost c...
CVE-2026-47667HIGH7.5CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field i...
CVE-2026-46600HIGH7.5Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
CVE-2026-46403MEDIUM6.3Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithT...
CVE-2026-42397MEDIUM6.5Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A...
CVE-2026-30632HIGH7.5Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool.
CVE-2026-15957HIGH8.7Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface ...
CVE-2026-64877HIGH8.4An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stor...
CVE-2026-63454HIGH7.2An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an ...
CVE-2026-63453HIGH7.2Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerab...
CVE-2026-59142CRITICAL9.1Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and leng...
CVE-2026-59141CRITICAL9.1Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices...
CVE-2026-59140CRITICAL9.1Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the ra...
CVE-2026-59139CRITICAL9.1Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and lengt...
CVE-2026-55084HIGH8.8DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL inje...
CVE-2026-55082HIGH8.7DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. DHIS2 SQL ...
CVE-2026-55081HIGH7.3DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. The DHIS2 ...
CVE-2026-16441CRITICAL9.6In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been...
CVE-2026-12548MEDIUM4.2A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch betw...
CVE-2026-12547LOW3.4SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When th...
CVE-2016-20096CRITICAL9.8Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows r...
CVE-2026-56583LOW3.1HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session h...
CVE-2026-56582LOW3.1HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sen...
CVE-2026-56581LOW2.6HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session ...