CVE Vulnerability Database
Search and browse 390,037 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59895 | MEDIUM | 6.1 | 0.2% | Jul 8, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in... |
| CVE-2026-59892 | HIGH | 7.5 | 0.4% | Jul 8, 2026 | OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. Prior to 2.9.0, @opentelemetry/propagator-jaeger decode... |
| CVE-2026-59890 | MEDIUM | 6.1 | 0.3% | Jul 8, 2026 | setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to ... |
| CVE-2026-59887 | HIGH | 7.5 | 0.6% | Jul 8, 2026 | linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used b... |
| CVE-2026-59883 | MEDIUM | 6.1 | 0.1% | Jul 8, 2026 | Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bar... |
| CVE-2026-59882 | MEDIUM | 6.5 | 0.2% | Jul 8, 2026 | guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not ... |
| CVE-2026-59879 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#... |
| CVE-2026-59731 | HIGH | 8.2 | 0.3% | Jul 8, 2026 | Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially deco... |
| CVE-2026-59261 | MEDIUM | 6.5 | 0.1% | Jul 8, 2026 | OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provide... |
| CVE-2026-42505 | MEDIUM | 5.3 | 0.4% | Jul 8, 2026 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of... |
| CVE-2026-39822 | HIGH | 7.8 | 0.2% | Jul 8, 2026 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina... |
| CVE-2026-29009 | CRITICAL | 9.8 | 0.5% | Jul 8, 2026 | U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFI... |
| CVE-2026-29008 | HIGH | 8.7 | 0.4% | Jul 8, 2026 | U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c... |
| CVE-2026-29007 | MEDIUM | 6.9 | 0.5% | Jul 8, 2026 | U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFI... |
| CVE-2025-3110 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote at... |
| CVE-2026-9074 | CRITICAL | 9.8 | 0.4% | Jul 8, 2026 | IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulner... |
| CVE-2026-59880 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, Immutable.Map and Immutable.S... |
| CVE-2026-59877 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed opt... |
| CVE-2026-59876 | MEDIUM | 4.8 | 0.2% | Jul 8, 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text For... |
| CVE-2026-59875 | MEDIUM | 5.3 | 0.3% | Jul 8, 2026 | node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX ... |
| CVE-2026-59874 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar he... |
| CVE-2026-59873 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds... |
| CVE-2026-59871 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and lin... |
| CVE-2026-59870 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.1, YAML11_SCHEMA support for the !!omap tag in src... |
| CVE-2026-59869 | HIGH | 7.5 | 0.4% | Jul 8, 2026 | js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend ... |
