CVE search

400,976 results
CVE-2026-103600HIGHUnbounded ASN.1 nesting depth causes process-terminating stack overflowEPSS 0.3%CVE-2026-63578HIGHUnbounded PBE iteration count when decrypting PKCS#8 private keysEPSS 0.3%CVE-2026-63577HIGHName Constraints bypass: directoryName constraint matched at any position in the DN instead of as a prefixEPSS 0.2%CVE-2026-63576HIGHURI name constraints checked against a mis-parsed hostEPSS 0.2%CVE-2026-63575HIGHPKCS#12 key derivation loops about 2^32 times on a zero or negative iteration countEPSS 0.2%CVE-2026-63574HIGHUnbounded allocation from OpenPGP signature and user attribute subpacket lengthsEPSS 0.3%CVE-2026-63573HIGHBleichenbacher padding oracle in CMS RSA PKCS#1 v1.5 key-transport unwrapEPSS 0.3%CVE-2026-63572HIGHUnbounded MAC and bag-decryption iteration counts when loading PKCS#12 filesEPSS 0.3%CVE-2026-63571HIGHAttribute certificate path validation does not verify the attribute certificate's signatureEPSS 0.2%CVE-2026-63570HIGHPkcs12Store.GetCertificateChain loops forever on cyclic issuer linksEPSS 0.2%CVE-2026-63569CRITICALMTI/A0 DHAgreement does not validate the peer's ephemeral valueEPSS 0.4%CVE-2026-63568HIGHUnbounded CMP/CRMF password-based MAC iteration count allows CPU exhaustionEPSS 0.3%CVE-2026-63567HIGHIesEngine block-cipher mode checks padding before MAC (CBC padding oracle)EPSS 0.5%CVE-2026-63566HIGHDTLS handshake reassembler allocates buffer from unchecked 24-bit lengthEPSS 0.4%CVE-2026-97219MEDIUMMStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' ParameterEPSS 0.2%CVE-2026-92924MEDIUMUnlimited Elements For Elementor < 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via get_addon_output_dataEPSS 0.2%CVE-2026-91020MEDIUMWebToffee Gift Cards for WooCommerce < 1.3.1 - Unauthenticated Gift Card Amount Manipulation via wt_credit_amountEPSS 0.3%CVE-2026-90987MEDIUMEasy PayPal & Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulation via Client-Supplied PriceEPSS 0.2%CVE-2026-90952MEDIUMWP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access Mode Bypass via REST APIEPSS 0.2%CVE-2026-85005MEDIUMPopup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing AuthorizationEPSS 0.2%