CVE Vulnerability Database
Search and browse 390,049 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55433 | MEDIUM | 5.4 | 0.4% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55432 | MEDIUM | 5.4 | 0.3% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55431 | MEDIUM | 6.1 | 0.4% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55430 | MEDIUM | 6.8 | 0.2% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55429 | HIGH | 8.7 | 0.5% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55428 | HIGH | 8.2 | 0.4% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55427 | HIGH | 8.3 | 0.5% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55079 | MEDIUM | 6.5 | 0.6% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.24.0 and pr... |
| CVE-2026-59705 | CRITICAL | 9.8 | 0.5% | Jul 7, 2026 | mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers t... |
| CVE-2026-59704 | HIGH | 7.1 | 0.2% | Jul 7, 2026 | Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metada... |
| CVE-2026-55078 | MEDIUM | 6.5 | 0.6% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.17.0 and pr... |
| CVE-2026-55077 | HIGH | 7.2 | 0.6% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55076 | HIGH | 7.4 | 0.5% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-51937 | HIGH | 7.5 | 0.4% | Jul 7, 2026 | An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsAp... |
| CVE-2026-50811 | MEDIUM | 6.5 | 0.3% | Jul 7, 2026 | An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736... |
| CVE-2026-50810 | MEDIUM | 5.5 | 0.1% | Jul 7, 2026 | A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master HEAD before commit b35... |
| CVE-2026-37271 | CRITICAL | 9.8 | 0.4% | Jul 7, 2026 | Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GA... |
| CVE-2026-37270 | CRITICAL | 9.8 | 0.4% | Jul 7, 2026 | Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper passwor... |
| CVE-2026-36163 | MEDIUM | 5.4 | 0.2% | Jul 7, 2026 | An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execut... |
| CVE-2026-36162 | MEDIUM | 5.4 | 0.1% | Jul 7, 2026 | An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 all... |
| CVE-2026-14895 | HIGH | 7.5 | 0.2% | Jul 7, 2026 | String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtri... |
| CVE-2026-14740 | CRITICAL | 9.1 | 0.4% | Jul 7, 2026 | DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The pr... |
| CVE-2026-14739 | CRITICAL | 9.8 | 0.4% | Jul 7, 2026 | DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeho... |
| CVE-2026-14380 | HIGH | 8.8 | 0.5% | Jul 7, 2026 | DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is ass... |
| CVE-2026-59706 | CRITICAL | 9.3 | 0.3% | Jul 7, 2026 | mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request f... |
