CVE Vulnerability Database
Search and browse 390,029 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58306 | MEDIUM | 6.1 | — | Jul 9, 2026 | Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Es... |
| CVE-2026-58305 | MEDIUM | 6.1 | — | Jul 9, 2026 | Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Point... |
| CVE-2026-58304 | MEDIUM | 6.1 | — | Jul 9, 2026 | Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This iss... |
| CVE-2026-58303 | MEDIUM | 6.1 | — | Jul 9, 2026 | Stack-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects E... |
| CVE-2026-56291 | CRITICAL | 9.8 | 8.6% | Jul 9, 2026 | Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension B... |
| CVE-2026-56289 | MEDIUM | 5.5 | 0.1% | Jul 9, 2026 | GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff... |
| CVE-2026-56288 | MEDIUM | 5.5 | 0.1% | Jul 9, 2026 | GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Impro... |
| CVE-2026-50644 | HIGH | 8.6 | — | Jul 9, 2026 | SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all right... |
| CVE-2026-4298 | MEDIUM | 4.3 | — | Jul 9, 2026 | The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and includ... |
| CVE-2026-4275 | HIGH | 8.8 | — | Jul 9, 2026 | The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request F... |
| CVE-2026-14372 | HIGH | 7.1 | — | Jul 9, 2026 | The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is v... |
| CVE-2026-13441 | HIGH | 7.2 | — | Jul 9, 2026 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2026-12590 | MEDIUM | 5.9 | — | Jul 9, 2026 | Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an i... |
| CVE-2026-12428 | MEDIUM | 6.5 | — | Jul 9, 2026 | The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ... |
| CVE-2026-5955 | CRITICAL | 9.8 | 0.4% | Jul 9, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software an... |
| CVE-2026-5793 | MEDIUM | 6.1 | 0.3% | Jul 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software an... |
| CVE-2026-56460 | MEDIUM | 6.5 | 0.4% | Jul 9, 2026 | HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API respons... |
| CVE-2026-56459 | MEDIUM | 5.5 | 0.2% | Jul 9, 2026 | HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The application stores potentially s... |
| CVE-2026-56458 | HIGH | 7.5 | 0.2% | Jul 9, 2026 | HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged action... |
| CVE-2026-2342 | CRITICAL | 9.3 | 0.4% | Jul 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Inform... |
| CVE-2026-1989 | HIGH | 7.5 | 0.4% | Jul 9, 2026 | Authorization bypass through User-Controlled key vulnerability in PAVO Financial Technology Solutions Inc. PAVO Pay allo... |
| CVE-2026-1365 | MEDIUM | 6.5 | 0.4% | Jul 9, 2026 | Insertion of sensitive information into sent data vulnerability in Sayax Energy Technologies Inc. OSOS allows Authentica... |
| CVE-2026-15158 | CRITICAL | 9.8 | 1.0% | Jul 9, 2026 | The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, ... |
| CVE-2026-12433 | MEDIUM | 4.3 | 0.4% | Jul 9, 2026 | The Hydra Booking – Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Obje... |
| CVE-2026-8996 | MEDIUM | 6.5 | 0.3% | Jul 9, 2026 | The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve... |
