CVE Vulnerability Database
Search and browse 390,126 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55110 | MEDIUM | 6.1 | 0.2% | Jul 2, 2026 | A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (COR... |
| CVE-2026-54409 | HIGH | 8.1 | 0.2% | Jul 2, 2026 | A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulne... |
| CVE-2026-54408 | CRITICAL | 9.8 | 0.3% | Jul 2, 2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Prote... |
| CVE-2026-54407 | HIGH | 8.6 | 0.3% | Jul 2, 2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Prote... |
| CVE-2026-54406 | HIGH | 8.7 | 0.3% | Jul 2, 2026 | A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in s... |
| CVE-2026-54405 | HIGH | 7.5 | — | Jul 2, 2026 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Net... |
| CVE-2026-54404 | HIGH | 8.8 | 0.2% | Jul 2, 2026 | A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vu... |
| CVE-2026-54403 | HIGH | 8.6 | 0.5% | Jul 2, 2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices runni... |
| CVE-2026-54402 | HIGH | 8.8 | 0.8% | Jul 2, 2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability... |
| CVE-2026-54401 | HIGH | 8.8 | 0.2% | Jul 2, 2026 | A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to es... |
| CVE-2026-54400 | CRITICAL | 9.1 | 0.5% | Jul 2, 2026 | A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability ... |
| CVE-2026-53358 | HIGH | 8.8 | 0.2% | Jul 2, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close channels ... |
| CVE-2026-53357 | HIGH | 8 | 0.2% | Jul 2, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() v... |
| CVE-2026-50748 | CRITICAL | 9.9 | 1.2% | Jul 2, 2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability... |
| CVE-2026-50747 | CRITICAL | 9.9 | 0.2% | Jul 2, 2026 | A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vu... |
| CVE-2026-50746 | CRITICAL | 10 | 2.5% | Jul 2, 2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Conne... |
| CVE-2026-12168 | HIGH | 7.8 | — | Jul 2, 2026 | An improper validation vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to escal... |
| CVE-2026-12167 | HIGH | 7.8 | — | Jul 2, 2026 | The Minifilter communication port for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to access p... |
| CVE-2026-12166 | MEDIUM | 5.5 | — | Jul 2, 2026 | A NULL pointer dereference vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to c... |
| CVE-2026-4767 | CRITICAL | 9.8 | — | Jul 2, 2026 | Missing authentication for critical function vulnerability in TR7 Cyber Defense Inc. WAF-ASP allows Authentication Abu... |
| CVE-2026-5524 | CRITICAL | 9.8 | — | Jul 2, 2026 | The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in al... |
| CVE-2026-58653 | MEDIUM | 5.3 | — | Jul 2, 2026 | PraisonAI before 0.1.7 fails to validate that project_id in issue create and update request bodies belongs to the URL wo... |
| CVE-2026-58652 | HIGH | 7.5 | 0.8% | Jul 2, 2026 | luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the lu... |
| CVE-2026-4772 | MEDIUM | 5.4 | — | Jul 2, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber Defens... |
| CVE-2026-4770 | MEDIUM | 4.6 | — | Jul 2, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber Defens... |
