CVE Vulnerability Database
Search and browse 391,091 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20458 | HIGH | 7.5 | 0.2% | Jul 1, 2026 | In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote escalation of p... |
| CVE-2026-20457 | MEDIUM | 5.3 | 0.2% | Jul 1, 2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service... |
| CVE-2026-14191 | HIGH | 7.8 | 0.3% | Jul 1, 2026 | An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeade... |
| CVE-2026-57963 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, an... |
| CVE-2026-57962 | MEDIUM | 5.3 | 0.2% | Jul 1, 2026 | A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitr... |
| CVE-2026-53488 | HIGH | 8.8 | 0.2% | Jul 1, 2026 | containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plu... |
| CVE-2026-41579 | LOW | 3.3 | 0.2% | Jul 1, 2026 | runc is a CLI tool for spawning and running containers according to the OCI specification. In versions prior to 1.3.6, 1... |
| CVE-2026-54903 | MEDIUM | 6.3 | 0.3% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.load ... |
| CVE-2026-54902 | MEDIUM | 6.3 | 0.3% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to version 3.17.2, is vulnerabl... |
| CVE-2026-54901 | MEDIUM | 6.3 | 0.3% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj::Pars... |
| CVE-2026-54900 | MEDIUM | 6.3 | 0.3% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, when in ... |
| CVE-2026-54899 | MEDIUM | 6.3 | 0.4% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to version 3.17.2, disabling sy... |
| CVE-2026-54898 | LOW | 2.1 | 0.1% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2,Oj::Parse... |
| CVE-2026-54897 | LOW | 2.1 | 0.1% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to 3.17.2, Oj::Doc iterators (e... |
| CVE-2026-54896 | LOW | 2.1 | 0.1% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, when in ... |
| CVE-2026-54592 | HIGH | 7.5 | 0.3% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj::Doc#... |
| CVE-2026-54502 | MEDIUM | 6.3 | 0.3% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.dump ... |
| CVE-2026-54500 | MEDIUM | 5.3 | 0.2% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load ... |
| CVE-2026-57995 | HIGH | 8.8 | 0.3% | Jun 30, 2026 | phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GR... |
| CVE-2026-56777 | MEDIUM | 5.3 | 0.3% | Jun 30, 2026 | n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in the Pytho... |
| CVE-2026-56700 | CRITICAL | 9.8 | 1.7% | Jun 30, 2026 | Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Sch... |
| CVE-2026-56415 | CRITICAL | 10 | 3.1% | Jun 30, 2026 | Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable... |
| CVE-2026-56413 | CRITICAL | 10 | 3.1% | Jun 30, 2026 | Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens ... |
| CVE-2026-56399 | MEDIUM | 5.3 | 0.3% | Jun 30, 2026 | Open WebUI before 0.6.27 contains a server-side request forgery vulnerability in the /api/v1/retrieval/process/web endpo... |
| CVE-2026-56377 | MEDIUM | 4.8 | 0.2% | Jun 30, 2026 | ImageMagick before 7.1.2-24 contains an incorrect policy check that allows attackers to create or truncate files disallo... |
