CVE search

401,023 results
CVE-2026-9032HIGHUnauthenticated Onboarding Connect NULL Pointer Dereference Denial of Service Vulnerability in TP-Link Tapo C120 & C200EPSS 0.1%CVE-2026-103923LOWKaTeX: Existing prototype pollution can bypass trust restrictionsEPSS 0.3%CVE-2026-68496HIGHjackson-dataformats-binary: Smile parser does not enforce StreamReadConstraints.maxNameLength, enabling memory-exhaustion denial of serviceEPSS 0.7%CVE-2026-68495HIGHjackson-dataformats-binary: CBOR parser does not enforce StreamReadConstraints.maxNameLength, enabling memory-exhaustion denial of serviceEPSS 0.7%CVE-2026-104018HIGHVxWorks 7 improper privilege managementEPSS 0.6%CVE-2026-97662MEDIUMArgument injection in the diff scan operation in AWS security-agent-mcp-server allows arbitrary host file creation, overwrite, and truncation outside the intended workspaceEPSS 0.1%CVE-2026-102294HIGHAuthenticated OS Command Injection in TL-WR841N IPv6 WAN ConfigurationEPSS 0.9%CVE-2026-103922CRITICALCapacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy pathEPSS 0.2%CVE-2026-103884MEDIUMKeycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file readEPSS 0.2%CVE-2026-56098MEDIUMRubygem-katello: improper authorization logic allows resource enumerationEPSS 0.3%CVE-2026-56097MEDIUMRubygem-katello: sql injection in registry proxy via labelsEPSS 0.2%CVE-2026-12542MEDIUMForeman: command injection in foreman-tailEPSS 0.6%CVE-2026-12545MEDIUMRubygem-hammer_cli: command injection via insecure editor invocationEPSS 0.5%CVE-2023-54404HIGHZod 4.6.5 Uncontrolled Resource Consumption via Array ValidationEPSS 0.3%CVE-2026-73976HIGHdjehuty: Unauthenticated SPARQL injection in the search API (`order`, `operator`, `key`)EPSS 0.4%CVE-2026-21833LOWHCL AION is susceptible to a Missing "Content-Security-Policy" header Vulnerability (CVE-2026-21833)EPSS 0.2%CVE-2026-73975HIGHdjehuty: Authenticated SPARQL injection in session editing allows writing arbitrary RDF triplesEPSS 0.3%CVE-2026-77387MEDIUMgeopy: Regular Expression Denial of Service (ReDoS) in geopy.PointEPSS 0.2%CVE-2026-103921HIGHGraphQL Tools: TLS Certificate Validation Disabled in Legacy GraphQL WebSocket ExecutorEPSS 0.3%CVE-2026-96658CRITICALForeman: safemode bypass leading to rceEPSS 0.7%