CVE search
374,417 resultsCVE-2026-72522MEDIUMlibexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates dEPSS —CVE-2026-19389HIGHGstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflow in asfdemux bounds checks leading to out-of-bounds readEPSS —CVE-2026-19387HIGHGstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write in adpcmdec ima/dvi adpcm decoderEPSS —CVE-2026-19384MEDIUMSourceCodester Simple Doctors Appointment System ajax.php set_appointment sql injectionEPSS —CVE-2026-19383MEDIUMsaithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestricted uploadEPSS —CVE-2026-19382MEDIUMAlmico Speedfan MSR Index speedfan.sys KiSystemCall64 memory leakEPSS —CVE-2026-19381HIGHKingston FURY CTRL RGB Control Software Driver NTIOLib_KSFX.sys privileges managementEPSS —CVE-2026-19380MEDIUMMullvad wireguard.sys IOCTL AdapterState reference countEPSS —CVE-2026-19379MEDIUMEFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injectionEPSS —CVE-2026-19378MEDIUMcode-projects Task Management System CommentSave.php cross site scriptingEPSS —CVE-2026-19376MEDIUMUasoft Badaso File API api.php class permissionEPSS —CVE-2026-19375MEDIUMdmitriiweb article-scraper-mcp server.py fetch_article server-side request forgeryEPSS —CVE-2026-19374MEDIUMadafap api-mcp Proxy API Endpoint route.ts customAxios server-side request forgeryEPSS —CVE-2026-12372LOWServer-Side Request Forgery (SSRF) in nltk/nltkEPSS —CVE-2026-19373MEDIUMPhialsBasement KoboldCPP-MCP-Server BaseConfigSchema index.ts makeRequest server-side request forgeryEPSS —CVE-2026-19372MEDIUMHandwriting-OCR handwriting-ocr-mcp-server upload_document index.ts fs.readFileSync path traversalEPSS —CVE-2026-19371MEDIUMNikolaibibo claude-comfyui-mcp comfy_upload_image utils.ts copyFileSync path traversalEPSS —CVE-2026-19370MEDIUMbartekke8it56w2 new-mcp geminithinking index.ts fs.readFileSync path traversalEPSS —CVE-2026-19369MEDIUMKS-GEN-AI jira-mcp-server add_attachment_from_public_url index.ts axios.get server-side request forgeryEPSS —CVE-2026-19368MEDIUMPV-Bhat gemsuite-mcp gemini_search unified-gemini.ts path traversalEPSS —