CVE Vulnerability Database
Search and browse 390,004 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54329 | HIGH | 7.7 | — | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request ... |
| CVE-2026-53450 | HIGH | 7.4 | 0.3% | Jul 10, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, coturn rejects loopback peers by d... |
| CVE-2026-53449 | MEDIUM | 6 | 0.2% | Jul 10, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI co... |
| CVE-2026-53448 | HIGH | 7.2 | 0.7% | Jul 10, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.12.0, the coturn HTTPS admin panel passe... |
| CVE-2026-15146 | MEDIUM | 5.9 | 0.1% | Jul 10, 2026 | GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malici... |
| CVE-2025-30008 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users... |
| CVE-2025-30007 | HIGH | 8.8 | 2.1% | Jul 10, 2026 | HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticat... |
| CVE-2026-57476 | MEDIUM | 6.3 | 0.3% | Jul 10, 2026 | Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additio... |
| CVE-2026-57475 | MEDIUM | 6.9 | 0.3% | Jul 10, 2026 | Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed ... |
| CVE-2026-57474 | MEDIUM | 6.9 | 0.3% | Jul 10, 2026 | Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accept... |
| CVE-2026-56668 | HIGH | 8.1 | 0.2% | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for ur... |
| CVE-2026-56667 | HIGH | 7.3 | — | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL Login V2 OIDC and SAML FailedPreconditi... |
| CVE-2026-56666 | MEDIUM | 4.8 | 0.2% | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler ch... |
| CVE-2026-56665 | MEDIUM | 4.2 | — | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL is an open source identity m... |
| CVE-2026-56664 | MEDIUM | 4.2 | — | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Prov... |
| CVE-2026-55672 | HIGH | 7.4 | — | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchan... |
| CVE-2026-55671 | LOW | 2.3 | 0.3% | Jul 10, 2026 | ZITADEL is an open source identity management platform. From 4.0.0-rc.1 through 4.15.1, ZITADEL's HTTP notification chan... |
| CVE-2026-55670 | LOW | 2.3 | — | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the... |
| CVE-2026-53780 | — | — | — | Jul 10, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-2397 | CRITICAL | 9.8 | — | Jul 10, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automa... |
| CVE-2026-59193 | MEDIUM | 4.9 | — | Jul 10, 2026 | Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by ... |
| CVE-2026-59190 | HIGH | 8.7 | — | Jul 10, 2026 | grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages. In 1.10.5... |
| CVE-2026-59180 | LOW | 3.1 | — | Jul 10, 2026 | Apprise is an open source library which allows you to send a notification to almost all of the most popular notification... |
| CVE-2026-59162 | HIGH | 7.5 | 0.5% | Jul 10, 2026 | Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses... |
| CVE-2026-59161 | HIGH | 7.5 | 0.5% | Jul 10, 2026 | Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming w... |
