CVE Vulnerability Database
Search and browse 377,714 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71275 | MEDIUM | 5.4 | — | Aug 5, 2026 | OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML r... |
| CVE-2026-71274 | HIGH | 8.5 | 0.2% | Aug 5, 2026 | OpenBK7231T's CHANNEL_SetLabel (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel co... |
| CVE-2026-71273 | MEDIUM | 6.5 | 0.1% | Aug 5, 2026 | OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request w... |
| CVE-2026-71272 | HIGH | 8.5 | 0.2% | Aug 5, 2026 | Memos' webhook dispatch function safeDialContext (internal/webhook/webhook.go) resolves the target hostname via net.Defa... |
| CVE-2026-71271 | HIGH | 8.5 | 0.3% | Aug 5, 2026 | Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP against a reservedCIDR... |
| CVE-2026-71270 | HIGH | 8.6 | 0.3% | Aug 5, 2026 | Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanit... |
| CVE-2026-71269 | HIGH | 7.2 | 0.6% | Aug 5, 2026 | Node-RED's local-filesystem library storage module (getLibraryEntry and saveLibraryEntry in packages/node_modules/@node-... |
| CVE-2026-71268 | CRITICAL | 9.9 | 0.6% | Aug 5, 2026 | OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.s... |
| CVE-2026-71267 | CRITICAL | 9.8 | 0.3% | Aug 5, 2026 | microtar's mtar_write_file_header and mtar_write_dir_header functions (src/microtar.c) copy a caller-supplied entry name... |
| CVE-2026-71266 | HIGH | 7.8 | 0.1% | Aug 5, 2026 | tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl material file into a f... |
| CVE-2026-71265 | HIGH | 7.5 | 0.2% | Aug 5, 2026 | Domoticz's MochadTCP::MatchLine handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data ... |
| CVE-2026-71264 | HIGH | 8.2 | 0.2% | Aug 5, 2026 | WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson with no settings-PIN check, unlike ... |
| CVE-2026-71263 | CRITICAL | 9.1 | 0.3% | Aug 5, 2026 | The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). Th... |
| CVE-2026-71262 | CRITICAL | 9.8 | 0.6% | Aug 5, 2026 | IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (... |
| CVE-2026-71261 | HIGH | 7.8 | 0.1% | Aug 5, 2026 | dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk metadata parsing. I... |
| CVE-2026-71260 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (espho... |
| CVE-2026-71259 | HIGH | 8.6 | 0.1% | Aug 5, 2026 | ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py... |
| CVE-2026-71227 | MEDIUM | 5.1 | 0.1% | Aug 5, 2026 | A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO... |
| CVE-2026-71226 | HIGH | 7.3 | 0.1% | Aug 5, 2026 | Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all subm... |
| CVE-2026-71225 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stat... |
| CVE-2026-16022 | HIGH | 7.8 | — | Aug 5, 2026 | @oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constr... |
| CVE-2026-0516 | MEDIUM | 6.5 | — | Aug 5, 2026 | A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to... |
| CVE-2026-71256 | CRITICAL | 9.8 | 0.3% | Aug 5, 2026 | nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_iden... |
| CVE-2026-71255 | HIGH | 8.6 | 0.2% | Aug 5, 2026 | nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identification_res... |
| CVE-2026-71254 | CRITICAL | 9.8 | 0.5% | Aug 5, 2026 | nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (F... |
