CVE Vulnerability Database
Search and browse 390,162 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49119 | HIGH | 8.7 | 0.7% | Jul 1, 2026 | Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that all... |
| CVE-2026-47262 | MEDIUM | 5.5 | 0.5% | Jul 1, 2026 | containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vuln... |
| CVE-2026-41121 | HIGH | 7.8 | 0.1% | Jul 1, 2026 | Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Before File Access ('Lin... |
| CVE-2026-38142 | MEDIUM | 6.5 | 0.7% | Jul 1, 2026 | An unauthenticated command injection vulnerability in the /goform/fast_setting_internet_set endpoint of Tenda AC18 v15.0... |
| CVE-2026-14358 | MEDIUM | 6.1 | 0.3% | Jul 1, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun... |
| CVE-2026-13769 | MEDIUM | 6.8 | — | Jul 1, 2026 | Overly permissive file permissions in AWS CLI before 1.44.78 (v1) and 2.34.29 (v2) on Unix-like systems where the umask ... |
| CVE-2026-13760 | HIGH | 7.3 | — | Jul 1, 2026 | OS command injection in the NodejsFunction Docker bundling pipeline (OsCommand helper) in AWS aws-cdk-lib on all platfor... |
| CVE-2026-5051 | MEDIUM | 4.4 | 0.3% | Jul 1, 2026 | HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin dire... |
| CVE-2026-58521 | CRITICAL | 9.8 | 0.3% | Jul 1, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foun... |
| CVE-2026-58520 | MEDIUM | 6.1 | 0.3% | Jul 1, 2026 | URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener E... |
| CVE-2026-57737 | MEDIUM | 6.5 | — | Jul 1, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortco... |
| CVE-2026-57736 | HIGH | 7.4 | — | Jul 1, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. Thi... |
| CVE-2026-57723 | HIGH | 7.4 | — | Jul 1, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal.... |
| CVE-2026-57722 | MEDIUM | 5.9 | 0.1% | Jul 1, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable ... |
| CVE-2026-54428 | HIGH | 7.5 | 0.6% | Jul 1, 2026 | Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 an... |
| CVE-2026-51946 | MEDIUM | 6.5 | 0.3% | Jul 1, 2026 | SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.2.26) allows a remote attacker to execute arbitrary... |
| CVE-2026-49091 | HIGH | 8 | 0.2% | Jul 1, 2026 | Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forgin... |
| CVE-2026-49090 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (C... |
| CVE-2026-46680 | HIGH | 7.8 | 0.2% | Jul 1, 2026 | containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched... |
| CVE-2026-58454 | HIGH | 7.7 | 0.5% | Jul 1, 2026 | JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a remote code execution vulnerability that ... |
| CVE-2026-58453 | CRITICAL | 9.8 | 1.7% | Jul 1, 2026 | JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that... |
| CVE-2026-58452 | HIGH | 8.8 | 2.4% | Jul 1, 2026 | JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain an OS command injection vulnerability that ... |
| CVE-2026-57721 | MEDIUM | 5.3 | — | Jul 1, 2026 | Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2026-57720 | MEDIUM | 4.3 | — | Jul 1, 2026 | Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2026-57516 | HIGH | 8.8 | 0.5% | Jul 1, 2026 | Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to a... |
