CVE Vulnerability Database
Search and browse 390,079 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41515 | LOW | 3.3 | 0.1% | Jul 6, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-41514 | LOW | 3.3 | 0.1% | Jul 6, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-14898 | MEDIUM | 6.5 | 0.2% | Jul 6, 2026 | The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could pl... |
| CVE-2026-14536 | HIGH | 8.8 | 0.3% | Jul 6, 2026 | Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attack... |
| CVE-2026-11405 | CRITICAL | 9.8 | 0.2% | Jul 6, 2026 | The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8... |
| CVE-2026-9182 | CRITICAL | 9.8 | 0.3% | Jul 6, 2026 | Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this is... |
| CVE-2026-9181 | HIGH | 7.5 | 0.7% | Jul 6, 2026 | Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An una... |
| CVE-2026-55798 | MEDIUM | 4.5 | 0.1% | Jul 6, 2026 | Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by ... |
| CVE-2026-55380 | HIGH | 7.5 | 0.3% | Jul 6, 2026 | Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from t... |
| CVE-2026-55379 | HIGH | 7.5 | 0.4% | Jul 6, 2026 | Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field f... |
| CVE-2026-54291 | MEDIUM | 5.9 | 0.3% | Jul 6, 2026 | pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections ... |
| CVE-2026-54060 | HIGH | 7.5 | 0.3% | Jul 6, 2026 | Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into ... |
| CVE-2026-54059 | HIGH | 7.5 | 0.3% | Jul 6, 2026 | Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the P... |
| CVE-2026-13753 | HIGH | 7.5 | 0.5% | Jul 6, 2026 | Certain HP DeskJet All-in-One printers may be potentially vulnerable to information disclosure that allows an unauthenti... |
| CVE-2026-48614 | CRITICAL | 9.9 | — | Jul 6, 2026 | An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configurat... |
| CVE-2026-41434 | LOW | 3.3 | 0.1% | Jul 6, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-12154 | MEDIUM | 6.4 | 0.2% | Jul 6, 2026 | The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2026-48316 | CRITICAL | 10 | 1.1% | Jul 6, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re... |
| CVE-2026-43825 | HIGH | 7.3 | 4.8% | Jul 6, 2026 | Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected: before 3.0.0-M4 (libsvm document c... |
| CVE-2026-40257 | MEDIUM | 5.5 | 0.1% | Jul 6, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-40141 | CRITICAL | 9.9 | 0.4% | Jul 6, 2026 | A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote ... |
| CVE-2026-40140 | HIGH | 7.5 | 0.6% | Jul 6, 2026 | BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the ... |
| CVE-2026-40139 | CRITICAL | 9.8 | 0.7% | Jul 6, 2026 | A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improp... |
| CVE-2026-40138 | HIGH | 8.1 | 0.4% | Jul 6, 2026 | A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Pri... |
| CVE-2025-53831 | HIGH | 8.2 | — | Jul 6, 2026 | DrawIO for ownCloud is an application for using DrawIO with the file storage, synchronization, and sharing application o... |
