CVE Vulnerability Database
Search and browse 390,029 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59216 | CRITICAL | 9 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call de... |
| CVE-2026-59215 | LOW | 3.1 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread pa... |
| CVE-2026-59214 | CRITICAL | 9 | 0.2% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs c... |
| CVE-2026-59213 | MEDIUM | 5 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 before 0.10.0, get_all... |
| CVE-2026-59212 | MEDIUM | 5.4 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _verify_... |
| CVE-2026-59209 | MEDIUM | 6.5 | 0.3% | Jul 9, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with... |
| CVE-2026-58459 | CRITICAL | 9.6 | 1.8% | Jul 9, 2026 | gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows ... |
| CVE-2026-53987 | HIGH | 7.3 | 0.3% | Jul 9, 2026 | The Tag plugin for GLPI 11 before 2.14.4 stores the tag name without HTML sanitization and renders it into the Kanban ba... |
| CVE-2026-51606 | HIGH | 7.5 | 0.3% | Jul 9, 2026 | An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device t... |
| CVE-2026-51605 | HIGH | 7.5 | 0.4% | Jul 9, 2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unaut... |
| CVE-2026-51604 | HIGH | 7.5 | 0.4% | Jul 9, 2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauth... |
| CVE-2026-51603 | HIGH | 7.5 | 0.4% | Jul 9, 2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauth... |
| CVE-2026-51602 | HIGH | 7.5 | 0.4% | Jul 9, 2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauth... |
| CVE-2026-51601 | HIGH | 7.5 | 0.2% | Jul 9, 2026 | Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. The device fails to valid... |
| CVE-2026-51600 | HIGH | 7.5 | 0.4% | Jul 9, 2026 | Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIB... |
| CVE-2026-51599 | CRITICAL | 9.8 | 0.2% | Jul 9, 2026 | An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n al... |
| CVE-2026-51598 | MEDIUM | 6.5 | 0.2% | Jul 9, 2026 | An input validation vulnerability in the RTSP service of MERCURY MIPC252W IP Camera v1.0.5 Build 230306 Rel.79931n) allo... |
| CVE-2026-51597 | CRITICAL | 9.1 | 0.2% | Jul 9, 2026 | MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authenticat... |
| CVE-2026-15308 | HIGH | 7.5 | 0.6% | Jul 9, 2026 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark... |
| CVE-2026-15194 | LOW | 3.3 | 0.2% | Jul 9, 2026 | A security flaw has been discovered in Open5GS 2.7.7. This affects the function amf_context_final of the file src/amf/co... |
| CVE-2026-15193 | MEDIUM | 5.3 | — | Jul 9, 2026 | A vulnerability was determined in AidanPark openclaw-android up to 0.4.0. The affected element is an unknown function of... |
| CVE-2026-15192 | MEDIUM | 6.5 | 0.8% | Jul 9, 2026 | A vulnerability has been found in mettle sendportal up to 3.0.1. This issue affects the function sendgrid/postmark/posta... |
| CVE-2026-15191 | MEDIUM | 6.3 | 0.4% | Jul 9, 2026 | A flaw has been found in mettle sendportal up to 3.0.1. This vulnerability affects unknown code of the file vendor/mettl... |
| CVE-2026-15190 | HIGH | 7.3 | — | Jul 9, 2026 | A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown part of... |
| CVE-2026-13462 | HIGH | 7.5 | — | Jul 9, 2026 | PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to ... |
