CVE Vulnerability Database
Search and browse 389,990 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55804 | MEDIUM | 5.9 | 0.2% | Jul 10, 2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow... |
| CVE-2026-55803 | MEDIUM | 5.9 | 0.2% | Jul 10, 2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow... |
| CVE-2026-55187 | MEDIUM | 5.8 | 0.3% | Jul 10, 2026 | Mailpit is an email testing tool and API for developers. Prior to 1.30.2, the remediation shipped for CVE-2026-27808 is ... |
| CVE-2026-54736 | HIGH | 8.2 | 0.1% | Jul 10, 2026 | Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the... |
| CVE-2026-52761 | MEDIUM | 5.3 | 0.4% | Jul 10, 2026 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.... |
| CVE-2026-52747 | HIGH | 8.6 | 0.5% | Jul 10, 2026 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to ... |
| CVE-2026-49844 | MEDIUM | 5.9 | 0.8% | Jul 10, 2026 | Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces ... |
| CVE-2026-49394 | HIGH | 7.1 | 0.3% | Jul 10, 2026 | Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_pag... |
| CVE-2026-49213 | HIGH | 8.1 | 0.3% | Jul 10, 2026 | TypeBot is a chatbot builder tool. Prior to 3.17.2, Typebot's shared SSRF validator in packages/lib/src/ssrf/validateHtt... |
| CVE-2026-48127 | MEDIUM | 5.3 | 0.4% | Jul 10, 2026 | Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach... |
| CVE-2026-47422 | MEDIUM | 5.3 | 0.3% | Jul 10, 2026 | Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked approp... |
| CVE-2026-47199 | LOW | 2.3 | 0.4% | Jul 10, 2026 | Frappe is a full-stack web application framework. Prior to 16.18.3 and 15.108.0, check_safe_sql_query permitted SELECT I... |
| CVE-2026-44795 | HIGH | 8.8 | 1.0% | Jul 10, 2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3... |
| CVE-2026-42219 | MEDIUM | 6.9 | 0.5% | Jul 10, 2026 | Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, path traversal via download_backups was... |
| CVE-2026-41482 | HIGH | 7.1 | 0.3% | Jul 10, 2026 | Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion wer... |
| CVE-2026-15085 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI SEO/GEO ... |
| CVE-2026-15084 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Patterns... |
| CVE-2026-15083 | MEDIUM | 4.2 | 0.2% | Jul 10, 2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Cond... |
| CVE-2026-15082 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Siteimprove... |
| CVE-2026-15081 | HIGH | 7.4 | 0.3% | Jul 10, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Se... |
| CVE-2026-15080 | MEDIUM | 4.3 | 0.1% | Jul 10, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery. ... |
| CVE-2026-15079 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute Force. This... |
| CVE-2026-13244 | HIGH | 8.1 | 0.2% | Jul 10, 2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Ma... |
| CVE-2026-13243 | MEDIUM | 4.8 | 0.1% | Jul 10, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. This issue... |
| CVE-2026-13242 | MEDIUM | 6.5 | 0.2% | Jul 10, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation... |
