CVE Vulnerability Database
Search and browse 390,072 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58384 | HIGH | 7.8 | 0.2% | Jul 7, 2026 | A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation... |
| CVE-2026-13199 | MEDIUM | 5.1 | 0.1% | Jul 7, 2026 | EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. This resul... |
| CVE-2026-8377 | HIGH | 8.2 | 0.2% | Jul 7, 2026 | Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Colle... |
| CVE-2026-8309 | MEDIUM | 5.4 | 0.1% | Jul 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information... |
| CVE-2026-8306 | MEDIUM | 6.1 | 0.1% | Jul 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information... |
| CVE-2026-7380 | MEDIUM | 6.1 | 0.1% | Jul 7, 2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Techno... |
| CVE-2026-5799 | HIGH | 7.5 | 0.2% | Jul 7, 2026 | Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime a... |
| CVE-2026-5730 | HIGH | 7.5 | 0.2% | Jul 7, 2026 | Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime a... |
| CVE-2026-58315 | MEDIUM | 5.1 | 0.1% | Jul 7, 2026 | Cross-site request forgery vulnerability exists in SEIKO EPSON Web Config. If a user views a malicious page while logged... |
| CVE-2026-57871 | HIGH | 7.1 | 0.4% | Jul 7, 2026 | Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overw... |
| CVE-2026-57870 | MEDIUM | 5.3 | 0.2% | Jul 7, 2026 | Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document template... |
| CVE-2026-57869 | HIGH | 7.1 | 0.2% | Jul 7, 2026 | Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstat... |
| CVE-2026-57868 | HIGH | 7.1 | 0.2% | Jul 7, 2026 | MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. This issue affects M... |
| CVE-2026-57867 | HIGH | 8.8 | 0.3% | Jul 7, 2026 | MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit a... |
| CVE-2026-4375 | CRITICAL | 9 | 0.2% | Jul 7, 2026 | The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to... |
| CVE-2026-14345 | CRITICAL | 9.8 | 0.7% | Jul 7, 2026 | The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Re... |
| CVE-2026-12375 | CRITICAL | 9.8 | 0.1% | Jul 7, 2026 | The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny... |
| CVE-2026-12277 | HIGH | 8.7 | 0.1% | Jul 7, 2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input bef... |
| CVE-2026-10834 | MEDIUM | 4.6 | 0.1% | Jul 7, 2026 | The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile ima... |
| CVE-2026-42201 | LOW | 3.3 | 0.2% | Jul 7, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-34158 | HIGH | 8.8 | 0.4% | Jul 7, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-27844 | LOW | 2.7 | 0.2% | Jul 7, 2026 | Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated... |
| CVE-2026-27790 | LOW | 2.7 | 0.2% | Jul 7, 2026 | Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by ... |
| CVE-2026-26053 | MEDIUM | 5.3 | 0.2% | Jul 7, 2026 | An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator ... |
| CVE-2026-42200 | HIGH | 8.8 | — | Jul 7, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
