CVE Vulnerability Database

Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2024-32386HIGH7.3Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote at...
CVE-2024-32385MEDIUM4.3An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitiv...
CVE-2026-63397HIGH7.1remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL schema that is passed t...
CVE-2026-63089CRITICAL9.3WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation...
CVE-2026-62994LOW3.7CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreD...
CVE-2026-62963HIGH8.7Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidirectional WebSocket tr...
CVE-2026-62309HIGH7.5CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when...
CVE-2026-62299MEDIUM5.3CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an ...
CVE-2026-62290HIGH7.3cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the proc...
CVE-2026-61718MEDIUM5.4bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb w...
CVE-2026-61389HIGH7.3An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupt...
CVE-2026-60140MEDIUM6.9An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupti...
CVE-2026-60063HIGH7.3An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupt...
CVE-2026-55629HIGH8.7Whistle is an HTTP, HTTP2, HTTPS, and WebSocket debugging proxy. Prior to 2.10.3, lib/service/service.js handles GET /cg...
CVE-2026-54728MEDIUM6.1bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). Prior to BunkerWeb 1.6.12 and BunkerWeb ...
CVE-2026-49998HIGH8.2Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verif...
CVE-2026-44982HIGH7.2CrowdSec offers crowdsourced protection against malicious IPs. From 1.5.0 until 1.7.8, pkg/appsec/request.go NewParsedRe...
CVE-2026-44981HIGH8.2CrowdSec offers crowdsourced protection against malicious IPs. From 1.7.0 until 1.7.8, the LAPI router used gin-contrib/...
CVE-2026-15449MEDIUM5.8A time-of-check to time-of-use (TOCTOU) flaw in the illumos data-link pseudo-driver (dld) affects handling of the DLDIOC...
CVE-2026-15422CRITICAL9.1The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address ...
CVE-2026-15352HIGH8.2A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the a...
CVE-2026-54526CRITICAL9.9Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior t...
CVE-2026-53536MEDIUM5.3Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endp...
CVE-2026-53535MEDIUM5.9Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync feature clones a user-conf...
CVE-2026-47089MEDIUM4.3An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin acces...