CVE Vulnerability Database
Search and browse 390,037 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59821 | HIGH | 7.2 | 0.3% | Jul 8, 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's ... |
| CVE-2026-59820 | MEDIUM | 6.5 | 0.3% | Jul 8, 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Sk... |
| CVE-2026-59819 | MEDIUM | 4.9 | 0.3% | Jul 8, 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's... |
| CVE-2026-59807 | HIGH | 8.9 | 0.3% | Jul 8, 2026 | Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and ex... |
| CVE-2026-59806 | HIGH | 7.4 | 0.2% | Jul 8, 2026 | Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to re... |
| CVE-2026-59805 | HIGH | 7.1 | 0.2% | Jul 8, 2026 | Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authen... |
| CVE-2026-59804 | HIGH | 7.6 | 0.2% | Jul 8, 2026 | Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfigurat... |
| CVE-2026-59803 | HIGH | 8.7 | 0.4% | Jul 8, 2026 | rpcx through 1.9.3, fixed in commit 047aec1, contains a denial-of-service vulnerability in protocol.Message.Decode (prot... |
| CVE-2026-59802 | HIGH | 8.2 | 0.2% | Jul 8, 2026 | PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_ur... |
| CVE-2026-58501 | MEDIUM | 5.9 | 0.3% | Jul 8, 2026 | Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is defined but not enforced when parsing... |
| CVE-2026-58254 | MEDIUM | 6.5 | 0.4% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.... |
| CVE-2026-58253 | HIGH | 8.8 | 0.4% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.... |
| CVE-2026-58252 | MEDIUM | 6.5 | 0.5% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.... |
| CVE-2026-58251 | MEDIUM | 6.5 | 0.5% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.... |
| CVE-2026-58250 | HIGH | 7.5 | 0.7% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.... |
| CVE-2026-58214 | MEDIUM | 4.3 | 0.4% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.... |
| CVE-2026-58213 | HIGH | 7.1 | 0.4% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.1 and 2.... |
| CVE-2026-58212 | — | — | — | Jul 8, 2026 | Rejected reason: Further research determined the issue is not a vulnerability based on CNA Rule 4.1.12 The act of updati... |
| CVE-2026-58210 | HIGH | 7.5 | 0.7% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.... |
| CVE-2026-58209 | MEDIUM | 4.3 | 0.3% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.... |
| CVE-2026-55760 | HIGH | 7.5 | 0.4% | Jul 8, 2026 | Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.2, applications that pass us... |
| CVE-2026-55575 | HIGH | 8.2 | 0.4% | Jul 8, 2026 | LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.1, the pop array filt... |
| CVE-2026-55404 | HIGH | 8.8 | 0.6% | Jul 8, 2026 | yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, a... |
| CVE-2026-53624 | MEDIUM | 4.8 | 0.2% | Jul 8, 2026 | Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/hel... |
| CVE-2026-45045 | MEDIUM | 5.3 | 0.5% | Jul 8, 2026 | Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper i... |
