CVE Vulnerability Database
Search and browse 390,072 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21369 | MEDIUM | 5.3 | 0.1% | Jul 6, 2026 | Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification. |
| CVE-2026-21368 | MEDIUM | 5.3 | 0.1% | Jul 6, 2026 | Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks. |
| CVE-2026-14471 | HIGH | 8.6 | 0.3% | Jul 6, 2026 | Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-g... |
| CVE-2026-14468 | HIGH | 7.7 | 0.3% | Jul 6, 2026 | HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that... |
| CVE-2025-59617 | HIGH | 7.3 | 0.1% | Jul 6, 2026 | Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input. |
| CVE-2025-59616 | HIGH | 7.8 | 0.1% | Jul 6, 2026 | Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing alrea... |
| CVE-2025-59615 | HIGH | 7.8 | 0.1% | Jul 6, 2026 | Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffe... |
| CVE-2026-59089 | MEDIUM | 5.5 | 0.2% | Jul 6, 2026 | A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calc... |
| CVE-2026-58404 | MEDIUM | 6.8 | 0.2% | Jul 6, 2026 | Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests t... |
| CVE-2026-58403 | MEDIUM | 6.5 | 0.4% | Jul 6, 2026 | Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's virtual filesystem is designed so that files und... |
| CVE-2026-58402 | MEDIUM | 5.4 | 0.3% | Jul 6, 2026 | Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-f... |
| CVE-2026-55646 | MEDIUM | 6.5 | 0.3% | Jul 6, 2026 | vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions a... |
| CVE-2026-53763 | LOW | 3.8 | 0.1% | Jul 6, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-50134 | MEDIUM | 5.8 | 0.3% | Jul 6, 2026 | Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.http.urls on the URL i... |
| CVE-2026-50133 | MEDIUM | 6.1 | 0.3% | Jul 6, 2026 | Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to... |
| CVE-2026-44362 | MEDIUM | 5.5 | 0.1% | Jul 6, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-42546 | LOW | 3.8 | 0.1% | Jul 6, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-41516 | LOW | 3.3 | 0.1% | Jul 6, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-41515 | LOW | 3.3 | 0.1% | Jul 6, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-41514 | LOW | 3.3 | 0.1% | Jul 6, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-14898 | MEDIUM | 6.5 | 0.2% | Jul 6, 2026 | The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could pl... |
| CVE-2026-14536 | HIGH | 8.8 | 0.3% | Jul 6, 2026 | Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attack... |
| CVE-2026-11405 | CRITICAL | 9.8 | 0.2% | Jul 6, 2026 | The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8... |
| CVE-2026-9182 | CRITICAL | 9.8 | 0.3% | Jul 6, 2026 | Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this is... |
| CVE-2026-9181 | HIGH | 7.5 | 0.7% | Jul 6, 2026 | Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An una... |
