CVE Vulnerability Database
Search and browse 392,294 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46680 | HIGH | 7.8 | 0.2% | Jul 1, 2026 | containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched... |
| CVE-2026-58454 | HIGH | 7.7 | 0.5% | Jul 1, 2026 | JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a remote code execution vulnerability that ... |
| CVE-2026-58453 | CRITICAL | 9.8 | 1.7% | Jul 1, 2026 | JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that... |
| CVE-2026-58452 | HIGH | 8.8 | 2.4% | Jul 1, 2026 | JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain an OS command injection vulnerability that ... |
| CVE-2026-57721 | MEDIUM | 5.3 | — | Jul 1, 2026 | Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2026-57720 | MEDIUM | 4.3 | — | Jul 1, 2026 | Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2026-57516 | HIGH | 8.8 | 0.5% | Jul 1, 2026 | Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to a... |
| CVE-2026-56152 | MEDIUM | 5.3 | 0.3% | Jul 1, 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality ... |
| CVE-2026-56151 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An... |
| CVE-2026-56150 | HIGH | 7.5 | 0.3% | Jul 1, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Exces... |
| CVE-2026-56149 | MEDIUM | 4.9 | 0.3% | Jul 1, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce... |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.3% | Jul 1, 2026 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). ... |
| CVE-2026-54399 | HIGH | 7.5 | 0.6% | Jul 1, 2026 | Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and ... |
| CVE-2026-49088 | MEDIUM | 4.4 | 0.2% | Jul 1, 2026 | Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the option... |
| CVE-2026-49087 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A... |
| CVE-2026-34117 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in text_to_subtitles.php (line 19) ... |
| CVE-2026-34116 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.php (line 15) without... |
| CVE-2026-34115 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe_amazon.php (line 15) ... |
| CVE-2026-34114 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate_text.php (line 18) wit... |
| CVE-2026-34113 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech_text.php (line 18) withou... |
| CVE-2026-34112 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac.php (line 18) without ... |
| CVE-2026-34111 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac_text.php (line 18) wit... |
| CVE-2026-34110 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) with... |
| CVE-2026-34109 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (line 18) without san... |
| CVE-2026-34108 | CRITICAL | 9.8 | 0.5% | Jul 1, 2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanit... |
