CVE Vulnerability Database
Search and browse 390,029 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13461 | CRITICAL | 9.6 | 0.2% | Jul 9, 2026 | When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 ... |
| CVE-2026-61474 | MEDIUM | 5.3 | — | Jul 9, 2026 | An improper authorization check in MISP’s attribute creation endpoint allowed an authenticated user with permission to a... |
| CVE-2026-59208 | MEDIUM | 6.8 | 0.1% | Jul 9, 2026 | n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances confi... |
| CVE-2026-59207 | MEDIUM | 6.5 | — | Jul 9, 2026 | n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce th... |
| CVE-2026-59206 | HIGH | 7.1 | — | Jul 9, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with t... |
| CVE-2026-58125 | — | — | — | Jul 9, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-42486 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-23562 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-23561 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-23560 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-23559 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-23556 | CRITICAL | 9.4 | — | Jul 9, 2026 | When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ... |
| CVE-2026-15189 | MEDIUM | 6.3 | 0.4% | Jul 9, 2026 | A security vulnerability has been detected in aerostackdev aerostack-mcp up to 6315dfde7df0a15aaf743f88d91347115e09ba23.... |
| CVE-2026-15188 | MEDIUM | 6.3 | — | Jul 9, 2026 | A weakness has been identified in manjurulhoque django-job-portal up to dfa352f305bba44445ac5dc12e9b2a98c9dcd71f. Affect... |
| CVE-2026-15187 | MEDIUM | 4.3 | 0.4% | Jul 9, 2026 | A security flaw has been discovered in enquirer up to 2.4.1. Affected is the function Enquirer.set of the component Publ... |
| CVE-2026-11404 | HIGH | 7.5 | 0.6% | Jul 9, 2026 | Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello... |
| CVE-2025-58151 | CRITICAL | 9.4 | — | Jul 9, 2026 | varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF ... |
| CVE-2025-58146 | CRITICAL | 9.4 | — | Jul 9, 2026 | There are multiple issues. 1. Updates to the XAPI database sanitise input strings, but try generating the notifica... |
| CVE-2025-27464 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-27463 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-27462 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-60109 | HIGH | 8.7 | 0.5% | Jul 9, 2026 | Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol analyzer that allows unauth... |
| CVE-2026-60108 | HIGH | 8.7 | 0.4% | Jul 9, 2026 | Zeek before 8.0.9 contains an uncontrolled memory consumption vulnerability in the FTP analyzer that allows unauthentica... |
| CVE-2026-5005 | MEDIUM | 5.4 | — | Jul 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics... |
| CVE-2026-56292 | HIGH | 7.5 | 0.3% | Jul 9, 2026 | Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 10.11.1 - A SQLi vulnerability in AcyMailing... |
