The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.
For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
Legal Disclaimer:
Here is where you can read the NVD legal disclaimer.
-
CVE-2025-65945 - auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditions. Appli... read CVE-2025-65945
Published: December 04, 2025; 2:16:05 PM -0500 -
CVE-2025-71319 - image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Atta... read CVE-2025-71319
Published: June 09, 2026; 5:17:03 PM -0400 -
CVE-2026-54399 - Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending mes... read CVE-2026-54399
Published: July 01, 2026; 1:16:36 PM -0400 -
CVE-2026-54428 - Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending o... read CVE-2026-54428
Published: July 01, 2026; 2:16:34 PM -0400 -
CVE-2026-60222 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated at... read CVE-2026-60222
Published: July 21, 2026; 6:17:23 PM -0400 -
CVE-2026-60209 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated atta... read CVE-2026-60209
Published: July 21, 2026; 6:17:22 PM -0400 -
CVE-2026-60210 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with ne... read CVE-2026-60210
Published: July 21, 2026; 6:17:22 PM -0400 -
CVE-2026-60211 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated atta... read CVE-2026-60211
Published: July 21, 2026; 6:17:22 PM -0400 -
CVE-2026-60212 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated atta... read CVE-2026-60212
Published: July 21, 2026; 6:17:22 PM -0400 -
CVE-2026-60213 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with ... read CVE-2026-60213
Published: July 21, 2026; 6:17:22 PM -0400 -
CVE-2026-60214 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attac... read CVE-2026-60214
Published: July 21, 2026; 6:17:22 PM -0400 -
CVE-2026-60304 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attac... read CVE-2026-60304
Published: July 21, 2026; 6:17:33 PM -0400 -
CVE-2026-60283 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated atta... read CVE-2026-60283
Published: July 21, 2026; 6:17:30 PM -0400 -
CVE-2026-60284 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated atta... read CVE-2026-60284
Published: July 21, 2026; 6:17:30 PM -0400 -
CVE-2026-60285 - Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated atta... read CVE-2026-60285
Published: July 21, 2026; 6:17:30 PM -0400 -
CVE-2026-54999 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.
Published: July 14, 2026; 1:17:07 PM -0400 -
CVE-2026-55012 - Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.
Published: July 14, 2026; 1:17:09 PM -0400 -
CVE-2026-55011 - Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.
Published: July 14, 2026; 1:17:08 PM -0400 -
CVE-2026-55009 - Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
Published: July 14, 2026; 1:17:08 PM -0400 -
CVE-2026-55008 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Published: July 14, 2026; 1:17:08 PM -0400