CVE Vulnerability Database

Search and browse 389,948 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-40954LOW3.7CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 1...
CVE-2026-40953MEDIUM4.4CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers...
CVE-2026-40952HIGH7.8CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to...
CVE-2026-33443MEDIUM5.9CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledg...
CVE-2026-62947MEDIUM4.9OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io aut...
CVE-2026-62355MEDIUM5.4TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Rea...
CVE-2026-62353MEDIUM5.4TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/p...
CVE-2026-62351HIGH7.5TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/sr...
CVE-2026-62350HIGH7.2TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user wit...
CVE-2026-62349HIGH8.3TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, sourc...
CVE-2026-62348MEDIUM5.4TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allo...
CVE-2026-54443MEDIUM5.9Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssF...
CVE-2026-49988MEDIUM5.5Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP server attach_packed_...
CVE-2026-49987HIGH8.8Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, src/core/git/gitCommand.ts execGitSha...
CVE-2026-46485HIGH8.2Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated user...
CVE-2026-46421CRITICAL9.3The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-d...
CVE-2026-26032MEDIUM5.4The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a...
CVE-2026-15895HIGH8.4OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent ...
CVE-2026-15746MEDIUM6.9Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provide...
CVE-2026-12997HIGH7.5The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4...
CVE-2026-8055Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-48866. Reason: This candidate is a ...
CVE-2026-62948CRITICAL9.6OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN opt...
CVE-2026-62389Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as a duplicate of CVE-2026-48...
CVE-2026-61643MEDIUM5.9FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can...
CVE-2026-59258HIGH8.3immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that all...