CVE Vulnerability Database
Search and browse 393,247 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56249 | HIGH | 7.6 | 0.3% | Jun 30, 2026 | Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation endpoint that allows authen... |
| CVE-2026-56247 | HIGH | 8.8 | 0.3% | Jun 30, 2026 | Capgo before 12.128.2 allows org admins to assign org-scoped RBAC roles at app scope without validating role scope compa... |
| CVE-2026-56233 | HIGH | 8.7 | 0.5% | Jun 30, 2026 | Capgo before 12.128.2 contains a path traversal vulnerability in the builder upload proxy that allows authenticated user... |
| CVE-2026-56230 | HIGH | 8.8 | 0.3% | Jun 30, 2026 | Capgo before 12.128.2 contains a broken object level authorization vulnerability in middlewareKey() that accepts the cli... |
| CVE-2026-56224 | MEDIUM | 5.4 | 0.2% | Jun 30, 2026 | Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query parameters, automatica... |
| CVE-2026-56219 | HIGH | 8.7 | 0.3% | Jun 30, 2026 | Capgo before 12.128.2 contains a NULL-auth bypass vulnerability in the public.get_org_user_access_rbac function that all... |
| CVE-2026-55721 | CRITICAL | 9.3 | 0.4% | Jun 30, 2026 | Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debu... |
| CVE-2026-55223 | MEDIUM | 6.3 | 0.3% | Jun 30, 2026 | c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can c... |
| CVE-2026-54696 | LOW | 3.7 | 0.3% | Jun 30, 2026 | Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2.19.8 are vulnerable to heap buffer overflow when t... |
| CVE-2026-54673 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | electron-updater allows for automatic updates for Electron apps. Prior to 9.7.0, the HTTP redirect handler (HttpExecutor... |
| CVE-2026-54672 | HIGH | 7.8 | 0.1% | Jun 30, 2026 | electron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder... |
| CVE-2026-52198 | HIGH | 7.5 | 0.4% | Jun 30, 2026 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s... |
| CVE-2026-52197 | HIGH | 7.5 | 0.4% | Jun 30, 2026 | An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead... |
| CVE-2026-52195 | HIGH | 7.5 | 0.5% | Jun 30, 2026 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s... |
| CVE-2026-52193 | HIGH | 7.5 | 0.4% | Jun 30, 2026 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s... |
| CVE-2026-50110 | CRITICAL | 9.3 | 0.1% | Jun 30, 2026 | Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configu... |
| CVE-2026-50040 | MEDIUM | 6.1 | 0.2% | Jun 30, 2026 | Storage Concentrator (SC & SCVM) is vulnerable to reflected cross-site scripting due to unsanitized content being echoed... |
| CVE-2026-28322 | MEDIUM | 5.6 | 0.2% | Jun 30, 2026 | SolarWinds Database Performance Analyzer was found to be affected by a stored cross-site scripting vulnerability, which ... |
| CVE-2026-14156 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker wh... |
| CVE-2026-14155 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to... |
| CVE-2026-14154 | MEDIUM | 4.8 | 0.1% | Jun 30, 2026 | Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a use... |
| CVE-2026-14153 | MEDIUM | 5.3 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a u... |
| CVE-2026-14152 | CRITICAL | 9.6 | 0.2% | Jun 30, 2026 | Out of bounds read and write in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromi... |
| CVE-2026-14151 | HIGH | 8.3 | 0.2% | Jun 30, 2026 | Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised... |
| CVE-2026-14150 | MEDIUM | 5.4 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in Speech in Google Chrome prior to 150.0.7871.47 allowed a remote attacker w... |
