CVE Vulnerability Database

Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-34150HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and abov...
CVE-2026-33754MEDIUM6.5Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.9.0 and abov...
CVE-2026-33434HIGH7.1Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and abov...
CVE-2026-44453HIGH7.5h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Deni...
CVE-2026-44452MEDIUM5.9h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientH...
CVE-2026-44436HIGH7.5Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b...
CVE-2026-44435HIGH7.5Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 93...
CVE-2026-44434MEDIUM5.3Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit dc...
CVE-2026-44433HIGH7.5Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b...
CVE-2026-44182CRITICAL10Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kuber...
CVE-2026-44181CRITICAL10Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kuber...
CVE-2026-43978HIGH8.1wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their sess...
CVE-2026-43977HIGH7.5wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read anoth...
CVE-2026-15997LOW1.7Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffer...
CVE-2026-14253Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-11740Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-62826MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-59117HIGH7.5Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.
CVE-2026-58643MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an u...
CVE-2026-58598HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine all...
CVE-2026-57077HIGH7.7YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In t...
CVE-2026-57076HIGH7.8YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key i...
CVE-2026-57075CRITICAL9.1YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64...
CVE-2026-53412CRITICAL9.8Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Wind...
CVE-2026-53411HIGH7A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Cl...