CVE Vulnerability Database
Search and browse 390,117 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-26145 | CRITICAL | 9.8 | 0.3% | Jul 2, 2026 | Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-50722 | MEDIUM | 5.9 | 0.3% | Jul 2, 2026 | Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding o... |
| CVE-2026-50721 | MEDIUM | 5.9 | 0.4% | Jul 2, 2026 | Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authen... |
| CVE-2026-12413 | HIGH | 7.5 | 0.6% | Jul 2, 2026 | An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation wou... |
| CVE-2026-58460 | HIGH | 7.7 | 0.1% | Jul 2, 2026 | react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious applicat... |
| CVE-2026-52830 | CRITICAL | 9.4 | 0.4% | Jul 2, 2026 | fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining t... |
| CVE-2026-52192 | HIGH | 7.5 | 0.2% | Jul 2, 2026 | An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead... |
| CVE-2026-52191 | HIGH | 7.5 | 0.2% | Jul 2, 2026 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s... |
| CVE-2026-52189 | HIGH | 7.5 | 0.2% | Jul 2, 2026 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s... |
| CVE-2026-52188 | MEDIUM | 6.5 | 0.2% | Jul 2, 2026 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s... |
| CVE-2026-38972 | HIGH | 7.8 | 0.1% | Jul 2, 2026 | Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerability in the About-dialog code path in src/Not... |
| CVE-2026-38971 | CRITICAL | 9.1 | 0.5% | Jul 2, 2026 | ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_contr... |
| CVE-2026-38970 | HIGH | 7.5 | 0.5% | Jul 2, 2026 | pdfcpu through v0.11.1 contains an uncontrolled-recursion denial-of-service issue in pkg/pdfcpu/model/parse.go. The pars... |
| CVE-2026-38969 | — | — | 0.4% | Jul 2, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-38968 | CRITICAL | 9.8 | 0.4% | Jul 2, 2026 | ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session ide... |
| CVE-2026-59102 | MEDIUM | 5.4 | 0.2% | Jul 2, 2026 | Forgejo before 15.0.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execut... |
| CVE-2026-59101 | MEDIUM | 6.9 | 0.3% | Jul 2, 2026 | AutoBangumi before 3.2.8 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote ... |
| CVE-2026-59100 | MEDIUM | 5 | 0.2% | Jul 2, 2026 | LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows authenticated attackers to... |
| CVE-2026-59099 | CRITICAL | 9.3 | 0.4% | Jul 2, 2026 | Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to... |
| CVE-2026-59098 | HIGH | 7.1 | 0.2% | Jul 2, 2026 | LobeChat through 2.2.9 contains a broken access control vulnerability in the retrieval-augmented-generation semantic sea... |
| CVE-2026-59097 | MEDIUM | 6.9 | 0.3% | Jul 2, 2026 | Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to creat... |
| CVE-2026-59096 | HIGH | 8.2 | 0.2% | Jul 2, 2026 | Dapr Sentry's OIDC discovery endpoint derives the issuer and jwks_uri of the /.well-known/openid-configuration document ... |
| CVE-2026-59095 | HIGH | 8.3 | 0.2% | Jul 2, 2026 | LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attacker... |
| CVE-2026-59094 | HIGH | 8.7 | 0.5% | Jul 2, 2026 | Pathway through 0.31.1, fixed in commit d09722e, document store applies a caller-supplied glob pattern to indexed docume... |
| CVE-2026-59093 | HIGH | 8.8 | 0.4% | Jul 2, 2026 | Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions granted... |
