CVE Vulnerability Database

Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-48373HIGH7.8Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution i...
CVE-2026-46420CRITICAL9.8setup-php is a GitHub action to set up PHP with extensions, php.ini configuration, coverage drivers, and tools. From 2.2...
CVE-2026-45799HIGH7.5Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArra...
CVE-2026-45704HIGH7.1Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses i...
CVE-2026-45260HIGH8.1Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV ass...
CVE-2026-44974HIGH7.7@hapi/content provided HTTP Content-* headers parsing. Prior to 6.0.2, Content.disposition() retained the last occurrenc...
CVE-2026-44739HIGH8.7Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigActi...
CVE-2026-43636Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-42168CRITICAL9.1django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner ...
CVE-2026-36669CRITICAL9.8An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote ...
CVE-2026-16118HIGH7.1A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the ...
CVE-2026-15995MEDIUM4.2IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain inc...
CVE-2026-15415MEDIUM6.8AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure ...
CVE-2026-15322HIGH7.5IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the ...
CVE-2026-15093MEDIUM4.3IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to malicious websites due...
CVE-2026-15091CRITICAL9.3IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to imprope...
CVE-2026-15069MEDIUM5.4IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary script code due to imp...
CVE-2026-14979HIGH7.5IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ...
CVE-2026-14971HIGH7IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attac...
CVE-2026-14501CRITICAL9.8IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain se...
CVE-2026-14499HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elev...
CVE-2026-13473CRITICAL9.8IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulner...
CVE-2026-13448CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the...
CVE-2026-12283MEDIUM6.8Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard...
CVE-2025-51678HIGH7.5An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory address can lead to une...