CVE Vulnerability Database

Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-51677CRITICAL9.1An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or12...
CVE-2026-9171HIGH7.5IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused ...
CVE-2026-9135CRITICAL9.9IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) co...
CVE-2026-9103CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authenti...
CVE-2026-58195HIGH8.8Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, agentic-flow MCP server tools in src/mcp/standalone...
CVE-2026-53712HIGH8.2SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security L...
CVE-2026-52746HIGH7.5JSONata is a JSON query and transformation language. Prior to 2.2.0 and 1.8.9, malicious non-matching inputs to the $toM...
CVE-2026-50185LOW3.3RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-...
CVE-2026-49835HIGH7.5Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middle...
CVE-2026-48487MEDIUM5.3Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string a...
CVE-2026-48045MEDIUM6.5Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.12, AsyncListener.handle_que...
CVE-2026-47184MEDIUM6.5Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.7, DNSCache._async_add inser...
CVE-2026-47183MEDIUM6.5Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.6, DNSIncoming._log_exceptio...
CVE-2026-47180MEDIUM6.5Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.5, DNSIncoming._decode_label...
CVE-2026-45703MEDIUM6.4Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, the WordExport expor...
CVE-2026-45309HIGH7.5AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on to...
CVE-2026-45162HIGH8Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore loc...
CVE-2026-16073LOW3.5A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function S...
CVE-2026-9762HIGH7.8IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under u...
CVE-2026-9202CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow...
CVE-2026-9198CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER toke...
CVE-2026-50273HIGH7.5Datadog .NET Tracer is a client library for Datadog APM for .NET applications. Prior to 3.43.0, Datadog tracing librarie...
CVE-2026-48016MEDIUM4.3Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the Store API endpoint /store-api/handle-payment...
CVE-2026-48015MEDIUM4.9Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, SVG files are in the allowed_extensions whitelis...
CVE-2026-48014MEDIUM6.5Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the order state transition features /api/_action...