CVE Vulnerability Database
Search and browse 377,681 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5134 | CRITICAL | 9.8 | — | Aug 6, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Info... |
| CVE-2026-19041 | MEDIUM | 6.3 | 1.7% | Aug 6, 2026 | A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageSe... |
| CVE-2026-19040 | MEDIUM | 6.3 | 0.4% | Aug 6, 2026 | A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/... |
| CVE-2026-18501 | MEDIUM | 6.4 | 0.2% | Aug 6, 2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre... |
| CVE-2026-16731 | HIGH | 8.3 | — | Aug 6, 2026 | OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authe... |
| CVE-2026-16316 | MEDIUM | 4.3 | — | Aug 6, 2026 | OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame... |
| CVE-2026-16315 | HIGH | 8.7 | — | Aug 6, 2026 | OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authe... |
| CVE-2026-12605 | CRITICAL | 9.6 | 0.2% | Aug 6, 2026 | In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfrestt... |
| CVE-2026-70556 | MEDIUM | 5.1 | 0.1% | Aug 6, 2026 | Hubzilla versions prior to 11.4 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint h... |
| CVE-2026-66733 | HIGH | 8.7 | — | Aug 6, 2026 | Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enque... |
| CVE-2026-66732 | HIGH | 8.3 | — | Aug 6, 2026 | Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager whe... |
| CVE-2026-65551 | HIGH | 7.5 | 0.2% | Aug 6, 2026 | Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Securit... |
| CVE-2026-19039 | MEDIUM | 5.3 | 0.8% | Aug 6, 2026 | A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted ... |
| CVE-2026-19038 | MEDIUM | 6.3 | 0.5% | Aug 6, 2026 | A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function sc... |
| CVE-2026-19037 | MEDIUM | 4.3 | 0.4% | Aug 6, 2026 | A weakness has been identified in WonderTrader up to 0.9.9. This vulnerability affects the function MatchEngine::update_... |
| CVE-2026-19036 | HIGH | 7.3 | 2.5% | Aug 6, 2026 | A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/pp... |
| CVE-2026-15599 | LOW | 3.3 | — | Aug 6, 2026 | Unverified ownership vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-domain-joiner allow... |
| CVE-2026-0673 | MEDIUM | 5.3 | 0.2% | Aug 6, 2026 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to... |
| CVE-2026-8166 | MEDIUM | 5.4 | — | Aug 6, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Indu... |
| CVE-2026-68481 | HIGH | 7.5 | — | Aug 6, 2026 | In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospec... |
| CVE-2026-68079 | CRITICAL | 9.8 | — | Aug 6, 2026 | In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of ... |
| CVE-2026-65583 | CRITICAL | 9.1 | — | Aug 6, 2026 | Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim che... |
| CVE-2026-63687 | CRITICAL | 9.1 | — | Aug 6, 2026 | Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map witho... |
| CVE-2026-61466 | CRITICAL | 9.1 | — | Aug 6, 2026 | In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` val... |
| CVE-2026-5391 | MEDIUM | 6.4 | 0.2% | Aug 6, 2026 | The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute ... |
