CVE Vulnerability Database
Search and browse 390,057 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28378 | LOW | 2.7 | 0.1% | Jul 7, 2026 | The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organizatio... |
| CVE-2026-59707 | CRITICAL | 9.2 | 0.4% | Jul 7, 2026 | LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that al... |
| CVE-2026-58583 | HIGH | 8.4 | 0.1% | Jul 7, 2026 | FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege esc... |
| CVE-2026-58473 | CRITICAL | 9.3 | 0.4% | Jul 7, 2026 | Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite... |
| CVE-2026-58472 | HIGH | 7.1 | 0.2% | Jul 7, 2026 | GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string... |
| CVE-2026-58471 | HIGH | 7.1 | 0.2% | Jul 7, 2026 | GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() f... |
| CVE-2026-58470 | MEDIUM | 6.9 | 0.2% | Jul 7, 2026 | GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range(... |
| CVE-2026-58469 | HIGH | 8.7 | 0.4% | Jul 7, 2026 | GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_s... |
| CVE-2026-57172 | HIGH | 8.3 | 0.3% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded de... |
| CVE-2026-55647 | MEDIUM | 5.1 | 0.3% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, dashboard text components render stor... |
| CVE-2026-55635 | HIGH | 8.7 | 0.3% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed ... |
| CVE-2026-55633 | HIGH | 8.7 | 0.5% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and f... |
| CVE-2026-55631 | HIGH | 7.2 | 0.3% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the font management module allows aut... |
| CVE-2026-55592 | LOW | 3.9 | 0.3% | Jul 7, 2026 | Dashy is a self-hostable personal dashboard. Prior to 4.3.7, Dashy's workspace view trusts the url query parameter and a... |
| CVE-2026-55434 | MEDIUM | 6.5 | 0.5% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.33.0 and pr... |
| CVE-2026-55417 | MEDIUM | 6.9 | 0.2% | Jul 7, 2026 | Chevereto is a self-hosted media-sharing platform. Starting in version 3.7.5 and prior to version 4.5.4, when a user ena... |
| CVE-2026-53935 | MEDIUM | 6.9 | 0.3% | Jul 7, 2026 | Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 t... |
| CVE-2026-53751 | HIGH | 8.7 | 0.4% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the H2 database JDBC URL validation l... |
| CVE-2026-53730 | HIGH | 8.7 | 0.2% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql en... |
| CVE-2026-53729 | HIGH | 8.7 | 0.4% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, any authenticated user can download (... |
| CVE-2026-53511 | HIGH | 8.5 | 0.1% | Jul 7, 2026 | calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when... |
| CVE-2026-50530 | HIGH | 7.1 | 0.2% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface onl... |
| CVE-2026-50529 | HIGH | 8.7 | 0.3% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/share/proxyInfo share int... |
| CVE-2026-50007 | HIGH | 7.2 | 0.2% | Jul 7, 2026 | Actual is an open-source personal finance application. Prior to 26.7.0, a missing authorization issue allows a shared us... |
| CVE-2026-49471 | HIGH | 8.3 | 0.2% | Jul 7, 2026 | Serena is a powerful MCP toolkit for coding that provides semantic retrieval and editing capabilities. Prior to v1.5.2, ... |
