Ad

CVE Vulnerability Database

Complete database of CVE vulnerabilities. Track critical security threats, exploits and patches. Updated daily from NVD NIST.

CVE-2026-3020

8.6

Identity based authorization bypass vulnerability (IDOR) that allows an attacker to modify the data of a legitimate user account, such as changing the victim's email address, validating the new email …

Identity
Details

CVE-2026-32778

5.5

libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.

Libexpat Project
Details

CVE-2026-32777

5.5

libexpat before 2.7.5 allows an infinite loop while parsing DTD content.

Libexpat Project
Details

CVE-2026-32776

5.5

libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.

Libexpat_Project
Details

CVE-2026-32775

7.4

libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.

Libexif
Details

CVE-2026-32774

5.3

Vulnogram 1.0.0 contains a stored cross-site scripting vulnerability in comment hypertext handling that allows attackers to inject malicious scripts. Remote attackers can inject XSS payloads through comments to execute arbitrary …

Vulnogram
Details

CVE-2026-32772

3.4

telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.

telnet
Details

Lean 4 VS Code Extension is a Visual Studio Code extension for the Lean 4 proof assistant. Projects that use @leanprover/unicode-input-component are vulnerable to an XSS exploit in 0.1.9 of …

Lean
Details

CVE-2026-32729

8.8

Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enforce any rate limiting, attempt counting, or account lockout mechanism. An attacker who has obtained …

Runtipi
Details

CVE-2026-32724

5.3

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc1, a heap-use-after-free is detected in the MavlinkShell::available() function. The issue is caused by a race condition between the …

Dronecode
Details
632/3864