CVE Vulnerability Database
Search and browse 389,982 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22098 | CRITICAL | 9.2 | 0.3% | Jul 13, 2026 | Various sensitive information such as passwords and charging card UIDs are written to log files. |
| CVE-2026-22097 | CRITICAL | 9.3 | 0.3% | Jul 13, 2026 | The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the... |
| CVE-2026-22096 | CRITICAL | 9.3 | 0.4% | Jul 13, 2026 | The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such a... |
| CVE-2026-22095 | CRITICAL | 9.3 | 1.0% | Jul 13, 2026 | The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection. |
| CVE-2026-22093 | CRITICAL | 9.5 | 0.2% | Jul 13, 2026 | The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided b... |
| CVE-2026-15557 | HIGH | 7.3 | 0.5% | Jul 13, 2026 | A weakness has been identified in waooAI waoowaoo up to 0.4.1. Affected by this vulnerability is the function getInterna... |
| CVE-2026-15548 | HIGH | 8.8 | 0.7% | Jul 13, 2026 | A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. This vulnerability affects the function sub... |
| CVE-2026-14846 | MEDIUM | 4.5 | 0.3% | Jul 13, 2026 | In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by i... |
| CVE-2026-13014 | CRITICAL | 9.2 | 0.7% | Jul 13, 2026 | A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute... |
| CVE-2026-9708 | MEDIUM | 4.9 | 0.2% | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming w... |
| CVE-2026-9597 | MEDIUM | 5.4 | 0.1% | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before crea... |
| CVE-2026-9571 | MEDIUM | 6.5 | 0.2% | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon... |
| CVE-2026-6850 | MEDIUM | 6.5 | 0.2% | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of m... |
| CVE-2026-62143 | HIGH | 8.3 | 0.2% | Jul 13, 2026 | A Server-Side Request Forgery (SSRF) protection bypass existed in the html_to_markdown expansion module of misp-modules.... |
| CVE-2026-15574 | HIGH | 7.5 | 0.3% | Jul 13, 2026 | A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorizat... |
| CVE-2026-15547 | MEDIUM | 6.3 | 1.1% | Jul 13, 2026 | A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048 of the component CI... |
| CVE-2026-15546 | MEDIUM | 6.3 | 1.1% | Jul 13, 2026 | A security flaw has been discovered in Shibby Tomato up to 1.28.0000. Affected by this issue is the function sub_2D568 o... |
| CVE-2026-15545 | HIGH | 8.8 | 0.4% | Jul 13, 2026 | A vulnerability was identified in Shibby Tomato up to 1.28.0000. Affected by this vulnerability is the function main of ... |
| CVE-2026-14453 | CRITICAL | 9.6 | 0.5% | Jul 13, 2026 | This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that l... |
| CVE-2026-10106 | MEDIUM | 6.5 | 0.2% | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced i... |
| CVE-2026-10103 | MEDIUM | 4.3 | 0.1% | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared ... |
| CVE-2026-10085 | MEDIUM | 5.4 | 0.2% | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained chann... |
| CVE-2026-57830 | CRITICAL | 9.1 | 0.2% | Jul 13, 2026 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla exten... |
| CVE-2026-57829 | MEDIUM | 6.1 | 0.1% | Jul 13, 2026 | Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ul... |
| CVE-2026-4769 | CRITICAL | 9.8 | 0.4% | Jul 13, 2026 | Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startu... |
