CVE Vulnerability Database
Search and browse 394,050 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54502 | MEDIUM | 6.3 | 0.3% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.dump ... |
| CVE-2026-54500 | MEDIUM | 5.3 | 0.2% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load ... |
| CVE-2026-57995 | HIGH | 8.8 | 0.3% | Jun 30, 2026 | phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GR... |
| CVE-2026-56777 | MEDIUM | 5.3 | 0.3% | Jun 30, 2026 | n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in the Pytho... |
| CVE-2026-56700 | CRITICAL | 9.8 | 1.7% | Jun 30, 2026 | Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Sch... |
| CVE-2026-56415 | CRITICAL | 10 | 3.1% | Jun 30, 2026 | Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable... |
| CVE-2026-56413 | CRITICAL | 10 | 3.1% | Jun 30, 2026 | Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens ... |
| CVE-2026-56399 | MEDIUM | 5.3 | 0.3% | Jun 30, 2026 | Open WebUI before 0.6.27 contains a server-side request forgery vulnerability in the /api/v1/retrieval/process/web endpo... |
| CVE-2026-56377 | MEDIUM | 4.8 | 0.2% | Jun 30, 2026 | ImageMagick before 7.1.2-24 contains an incorrect policy check that allows attackers to create or truncate files disallo... |
| CVE-2026-56369 | MEDIUM | 6.3 | 0.2% | Jun 30, 2026 | ImageMagick before 7.1.2-22 contains an information disclosure vulnerability in the PasskeyEncipherImage method due to A... |
| CVE-2026-56365 | MEDIUM | 5.3 | 0.3% | Jun 30, 2026 | ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers c... |
| CVE-2026-56364 | LOW | 1.9 | 0.1% | Jun 30, 2026 | ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing ma... |
| CVE-2026-56363 | MEDIUM | 4.8 | 0.1% | Jun 30, 2026 | ImageMagick before 7.1.2-22 contains a division by zero vulnerability in binomial kernel processing that allows attacker... |
| CVE-2026-56361 | HIGH | 7.1 | 0.1% | Jun 30, 2026 | ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer rea... |
| CVE-2026-56356 | MEDIUM | 5.4 | 0.2% | Jun 30, 2026 | n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node's Custom CSS field due to a misconfigu... |
| CVE-2026-56350 | HIGH | 7.7 | 0.3% | Jun 30, 2026 | n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforce... |
| CVE-2026-56334 | MEDIUM | 5.3 | 0.2% | Jun 30, 2026 | Capgo before 12.128.2 lacks an UPDATE row-level security policy for the build_requests table, preventing API-key and ano... |
| CVE-2026-56333 | MEDIUM | 5.3 | 0.2% | Jun 30, 2026 | Capgo before 12.128.2 contains a server-side validation bypass vulnerability in organization security settings that allo... |
| CVE-2026-56331 | MEDIUM | 6.9 | 0.3% | Jun 30, 2026 | Capgo before 12.128.2 contains improper error handling in the /private/accept_invitation endpoint that returns HTTP 500 ... |
| CVE-2026-56328 | HIGH | 7.1 | 0.2% | Jun 30, 2026 | Capgo before 12.128.2 allows multiple public channels for the same app and platform to coexist simultaneously, while unn... |
| CVE-2026-56327 | MEDIUM | 6.9 | 0.3% | Jun 30, 2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the public.invite_user_to_org RPC function tha... |
| CVE-2026-56320 | HIGH | 7.1 | 0.2% | Jun 30, 2026 | Capgo before 12.128.2 contains an authorization flaw in POST /private/create_device that accepts a caller-supplied org_i... |
| CVE-2026-56318 | MEDIUM | 6.9 | 0.3% | Jun 30, 2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the /private/validate_password_compliance endp... |
| CVE-2026-56300 | HIGH | 8.7 | 0.3% | Jun 30, 2026 | Capgo before 12.128.2 contains unauthenticated security definer RPC functions get_user_id and get_org_perm_for_apikey th... |
| CVE-2026-56286 | HIGH | 8.1 | 0.4% | Jun 30, 2026 | Capgo before 12.128.2 contains an authentication bypass vulnerability in the account deletion endpoint that allows delet... |
