NVD Dashboard
CVEs Received and Processed
NVD Contains
| CVE Vulnerabilities | 370118 |
| Checklists | 898 |
| US-CERT Alerts | 249 |
| US-CERT Vuln Notes | 4486 |
| OVAL Queries | 0 |
| CPE Names | 1783563 |
CVSS V3 Score Distribution
| Severity | Number of Vulns |
|---|
CVSS V2 Score Distribution
| Severity | Number of Vulns |
|---|
For information on how to the cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
-
CVE-2025-65945 - auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditions. Appli... read CVE-2025-65945
Published: December 04, 2025; 2:16:05 PM -0500 -
CVE-2025-71319 - image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Atta... read CVE-2025-71319
Published: June 09, 2026; 5:17:03 PM -0400 -
CVE-2026-54399 - Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending mes... read CVE-2026-54399
Published: July 01, 2026; 1:16:36 PM -0400 -
CVE-2026-54428 - Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending o... read CVE-2026-54428
Published: July 01, 2026; 2:16:34 PM -0400 -
CVE-2026-60222 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated at... read CVE-2026-60222
Published: July 21, 2026; 6:17:23 PM -0400 -
CVE-2026-60209 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated atta... read CVE-2026-60209
Published: July 21, 2026; 6:17:22 PM -0400 -
CVE-2026-60210 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with ne... read CVE-2026-60210
Published: July 21, 2026; 6:17:22 PM -0400 -
CVE-2026-60211 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated atta... read CVE-2026-60211
Published: July 21, 2026; 6:17:22 PM -0400 -
CVE-2026-60212 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated atta... read CVE-2026-60212
Published: July 21, 2026; 6:17:22 PM -0400 -
CVE-2026-60213 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with ... read CVE-2026-60213
Published: July 21, 2026; 6:17:22 PM -0400 -
CVE-2026-60214 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attac... read CVE-2026-60214
Published: July 21, 2026; 6:17:22 PM -0400 -
CVE-2026-60304 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attac... read CVE-2026-60304
Published: July 21, 2026; 6:17:33 PM -0400 -
CVE-2026-60283 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated atta... read CVE-2026-60283
Published: July 21, 2026; 6:17:30 PM -0400 -
CVE-2026-60284 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated atta... read CVE-2026-60284
Published: July 21, 2026; 6:17:30 PM -0400 -
CVE-2026-60285 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated atta... read CVE-2026-60285
Published: July 21, 2026; 6:17:30 PM -0400 -
CVE-2026-54999 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.
Published: July 14, 2026; 1:17:07 PM -0400 -
CVE-2026-55012 - Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.
Published: July 14, 2026; 1:17:09 PM -0400 -
CVE-2026-55011 - Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.
Published: July 14, 2026; 1:17:08 PM -0400 -
CVE-2026-55009 - Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
Published: July 14, 2026; 1:17:08 PM -0400 -
CVE-2026-55008 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Published: July 14, 2026; 1:17:08 PM -0400