U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2025-65945 - auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditions. Appli... read CVE-2025-65945
    Published: December 04, 2025; 2:16:05 PM -0500

  • CVE-2025-71319 - image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Atta... read CVE-2025-71319
    Published: June 09, 2026; 5:17:03 PM -0400

  • CVE-2026-54399 - Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending mes... read CVE-2026-54399
    Published: July 01, 2026; 1:16:36 PM -0400

  • CVE-2026-54428 - Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending o... read CVE-2026-54428
    Published: July 01, 2026; 2:16:34 PM -0400

  • CVE-2026-60222 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated at... read CVE-2026-60222
    Published: July 21, 2026; 6:17:23 PM -0400

  • CVE-2026-60209 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated atta... read CVE-2026-60209
    Published: July 21, 2026; 6:17:22 PM -0400

  • CVE-2026-60210 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with ne... read CVE-2026-60210
    Published: July 21, 2026; 6:17:22 PM -0400

  • CVE-2026-60211 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated atta... read CVE-2026-60211
    Published: July 21, 2026; 6:17:22 PM -0400

  • CVE-2026-60212 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated atta... read CVE-2026-60212
    Published: July 21, 2026; 6:17:22 PM -0400

  • CVE-2026-60213 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with ... read CVE-2026-60213
    Published: July 21, 2026; 6:17:22 PM -0400

  • CVE-2026-60214 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attac... read CVE-2026-60214
    Published: July 21, 2026; 6:17:22 PM -0400

  • CVE-2026-60304 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attac... read CVE-2026-60304
    Published: July 21, 2026; 6:17:33 PM -0400

  • CVE-2026-60283 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated atta... read CVE-2026-60283
    Published: July 21, 2026; 6:17:30 PM -0400

  • CVE-2026-60284 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated atta... read CVE-2026-60284
    Published: July 21, 2026; 6:17:30 PM -0400

  • CVE-2026-60285 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated atta... read CVE-2026-60285
    Published: July 21, 2026; 6:17:30 PM -0400

  • CVE-2026-54999 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.
    Published: July 14, 2026; 1:17:07 PM -0400

  • CVE-2026-55012 - Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.
    Published: July 14, 2026; 1:17:09 PM -0400

  • CVE-2026-55011 - Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.
    Published: July 14, 2026; 1:17:08 PM -0400

  • CVE-2026-55009 - Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
    Published: July 14, 2026; 1:17:08 PM -0400

  • CVE-2026-55008 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
    Published: July 14, 2026; 1:17:08 PM -0400

Created September 20, 2022 , Updated August 27, 2024