CVE Vulnerability Database
Search and browse 390,079 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5268 | CRITICAL | 9.1 | 0.4% | Jul 6, 2026 | An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products li... |
| CVE-2026-59196 | HIGH | 7.1 | 0.3% | Jul 6, 2026 | pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoiste... |
| CVE-2026-59195 | HIGH | 8.2 | 0.2% | Jul 6, 2026 | pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependenc... |
| CVE-2026-59194 | HIGH | 7.1 | 0.2% | Jul 6, 2026 | pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patch... |
| CVE-2026-59152 | MEDIUM | 5 | 0.2% | Jul 6, 2026 | LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can se... |
| CVE-2026-58203 | MEDIUM | 5.3 | 0.2% | Jul 6, 2026 | pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource rea... |
| CVE-2026-13122 | MEDIUM | 5.3 | 0.5% | Jul 6, 2026 | OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service v... |
| CVE-2025-53830 | CRITICAL | 9.1 | 0.3% | Jul 6, 2026 | Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud... |
| CVE-2025-53829 | HIGH | 8 | 0.3% | Jul 6, 2026 | ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attack... |
| CVE-2025-53828 | HIGH | 8.5 | 0.2% | Jul 6, 2026 | SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing appli... |
| CVE-2025-53827 | CRITICAL | 9.1 | 0.3% | Jul 6, 2026 | ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classi... |
| CVE-2026-7185 | MEDIUM | 6 | — | Jul 6, 2026 | A validation vulnerability has been identified in certain web features related to file management or upload in several p... |
| CVE-2026-58380 | HIGH | 7.8 | 0.3% | Jul 6, 2026 | A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() ... |
| CVE-2026-54893 | LOW | 2.1 | — | Jul 6, 2026 | URL path injection in the Microsoft Graph adapter of Swoosh. Swoosh.Adapters.MsGraph builds its Microsoft Graph API requ... |
| CVE-2026-13698 | HIGH | 7.5 | 0.5% | Jul 6, 2026 | A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote a... |
| CVE-2026-13708 | HIGH | 7.5 | — | Jul 6, 2026 | Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_... |
| CVE-2026-13705 | HIGH | 7.1 | — | Jul 6, 2026 | Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bi... |
| CVE-2025-15668 | LOW | 3.3 | 0.1% | Jul 6, 2026 | A vulnerability was identified in GPAC up to b40ce70f5. This issue affects the function sgpd_del_entry of the file src/i... |
| CVE-2025-15667 | LOW | 3.3 | — | Jul 6, 2026 | A vulnerability was determined in GPAC up to 2.5-DEV. This vulnerability affects the function gf_isom_nalu_sample_rewrit... |
| CVE-2026-6901 | HIGH | 8.4 | — | Jul 6, 2026 | Untrusted Search Path vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P... |
| CVE-2026-6900 | CRITICAL | 9.1 | — | Jul 6, 2026 | Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before... |
| CVE-2026-58226 | HIGH | 8.7 | — | Jul 6, 2026 | Inefficient Algorithmic Complexity vulnerability in elixir-mint hpax allows unauthenticated denial-of-service via unboun... |
| CVE-2026-56810 | HIGH | 8.7 | — | Jul 6, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint (Mint.HTTP1 module) allows a deni... |
| CVE-2026-4249 | HIGH | 8.6 | 0.3% | Jul 6, 2026 | The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient... |
| CVE-2026-49297 | HIGH | 8.1 | 0.6% | Jul 6, 2026 | Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object ... |
