CVE Vulnerability Database
Search and browse 377,710 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16443 | CRITICAL | 9.1 | 0.1% | Aug 5, 2026 | A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine ... |
| CVE-2026-15979 | HIGH | 8.1 | 0.8% | Aug 5, 2026 | The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Del... |
| CVE-2025-70962 | HIGH | 7.5 | — | Aug 5, 2026 | Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials ... |
| CVE-2026-71294 | HIGH | 7.6 | 0.2% | Aug 5, 2026 | Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. ... |
| CVE-2026-71293 | MEDIUM | 6.2 | 0.2% | Aug 5, 2026 | Statamic CMS's user-augmentation resolver, AugmentedUser::get in src/Auth/AugmentedUser.php, contains an explicit case f... |
| CVE-2026-71292 | HIGH | 7.2 | 0.3% | Aug 5, 2026 | Subrion CMS's admin grid sorting helper, _gridGetSorting in includes/classes/ia.base.controller.admin.php, whitelists th... |
| CVE-2026-71291 | HIGH | 8.8 | 0.5% | Aug 5, 2026 | Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registe... |
| CVE-2026-71289 | CRITICAL | 9.8 | 0.4% | Aug 5, 2026 | The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publi... |
| CVE-2026-71288 | HIGH | 8.8 | 0.3% | Aug 5, 2026 | Koha's guided report builder (reports/guided_reports.pl) reads the CGI parameter and, for each value, a dynamically-name... |
| CVE-2026-71287 | HIGH | 8.8 | 0.3% | Aug 5, 2026 | Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . Because ... |
| CVE-2026-71286 | MEDIUM | 6.1 | 0.2% | Aug 5, 2026 | The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its property... |
| CVE-2026-71285 | HIGH | 8.1 | 0.2% | Aug 5, 2026 | Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo ... |
| CVE-2026-71284 | HIGH | 7.2 | 0.9% | Aug 5, 2026 | Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), takes the fir... |
| CVE-2026-71283 | MEDIUM | 4.9 | 0.3% | Aug 5, 2026 | Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), calls tarfile... |
| CVE-2026-71282 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | ChirpStack's SQLite-backend device tag filtering (chirpstack/src/storage/device.rs, in both get_count and list) interpol... |
| CVE-2026-71281 | HIGH | 8.8 | 0.3% | Aug 5, 2026 | Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src... |
| CVE-2026-71280 | HIGH | 8.5 | 0.2% | Aug 5, 2026 | go-shiori's DownloadBookmark (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Clien... |
| CVE-2026-71279 | HIGH | 8 | 0.4% | Aug 5, 2026 | Zigbee2MQTT's ExternalJSExtension.getFilePath (lib/extension/externalJS.ts) joins a parameter received via an MQTT messa... |
| CVE-2026-71278 | CRITICAL | 9.8 | 0.5% | Aug 5, 2026 | rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) cont... |
| CVE-2026-71277 | CRITICAL | 9.1 | 0.2% | Aug 5, 2026 | rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP ... |
| CVE-2026-71276 | HIGH | 7.1 | 0.2% | Aug 5, 2026 | Magistrala (formerly Mainflux)'s message-readers API reads a value from the HTTP query string (readers/api/http/transpor... |
| CVE-2026-71275 | MEDIUM | 5.4 | — | Aug 5, 2026 | OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML r... |
| CVE-2026-71274 | HIGH | 8.5 | 0.2% | Aug 5, 2026 | OpenBK7231T's CHANNEL_SetLabel (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel co... |
| CVE-2026-71273 | MEDIUM | 6.5 | 0.1% | Aug 5, 2026 | OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request w... |
| CVE-2026-71272 | HIGH | 8.5 | 0.2% | Aug 5, 2026 | Memos' webhook dispatch function safeDialContext (internal/webhook/webhook.go) resolves the target hostname via net.Defa... |
