CVE Vulnerability Database
Search and browse 390,222 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58399 | HIGH | 8.7 | 0.5% | Jul 1, 2026 | @acastellon/auth is an authentication control system for microservices. Versions prior to 2.3.0 appear to allow an unaut... |
| CVE-2026-58035 | MEDIUM | 4.8 | 0.2% | Jul 1, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-58034 | MEDIUM | 4.8 | 0.2% | Jul 1, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-58031 | MEDIUM | 5.4 | 0.2% | Jul 1, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-2891 | HIGH | 8.2 | 0.3% | Jul 1, 2026 | The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP serve... |
| CVE-2026-23537 | CRITICAL | 9.1 | 0.6% | Jul 1, 2026 | A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticat... |
| CVE-2026-14330 | MEDIUM | 5.5 | 0.1% | Jul 1, 2026 | Multiple unbounded alloca() calls in the PulseAudio protocol server. |
| CVE-2026-14324 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return. |
| CVE-2026-13602 | HIGH | 7.7 | 0.2% | Jul 1, 2026 | We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the ... |
| CVE-2026-12374 | MEDIUM | 6.4 | 0.1% | Jul 1, 2026 | Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC ... |
| CVE-2026-5136 | HIGH | 8.8 | 0.3% | Jul 1, 2026 | A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the call... |
| CVE-2026-57692 | CRITICAL | 9.8 | — | Jul 1, 2026 | Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects Pr... |
| CVE-2026-53356 | HIGH | 7.8 | 0.1% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Fix phys BO pread/pwrite with offset ... |
| CVE-2026-53355 | CRITICAL | 9.8 | 0.4% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB... |
| CVE-2026-53354 | HIGH | 8.8 | 0.1% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Mitigate TLBI errata on various Arm ... |
| CVE-2026-53353 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: hsr: Remove WARN_ONCE() in hsr_addr_is_self(). syz... |
| CVE-2026-53352 | MEDIUM | 4.7 | 0.1% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: signal: clear JOBCTL_PENDING_MASK for caller in zap... |
| CVE-2026-53351 | MEDIUM | 5.5 | 0.1% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: riscv/ptrace: Use USER_REGSET_NOTE_TYPE for REGSET_... |
| CVE-2026-53350 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: ASoC: wm_adsp: Fix NULL dereference when removing f... |
| CVE-2026-53349 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: destroy stale expectfn exp... |
| CVE-2026-53348 | — | — | 0.1% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: fix NULL pointer dereference in sdca_de... |
| CVE-2026-53347 | — | — | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix driver removal with disabled KMS D... |
| CVE-2026-53346 | — | — | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: rust: arm64: set uwtable llvm module flag for CONFI... |
| CVE-2026-53345 | — | — | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: Don't WARN if memory is dirtied without a vCPU... |
| CVE-2026-53344 | MEDIUM | 5.5 | 0.1% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: mcp23s08: Initialize mcp->dev and mcp->add... |
