CVE Vulnerability Database
Search and browse 377,718 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0516 | MEDIUM | 6.5 | — | Aug 5, 2026 | A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to... |
| CVE-2026-71256 | CRITICAL | 9.8 | 0.3% | Aug 5, 2026 | nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_iden... |
| CVE-2026-71255 | HIGH | 8.6 | 0.2% | Aug 5, 2026 | nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identification_res... |
| CVE-2026-71254 | CRITICAL | 9.8 | 0.5% | Aug 5, 2026 | nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (F... |
| CVE-2026-64582 | HIGH | 7.8 | 0.2% | Aug 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap ... |
| CVE-2026-61891 | HIGH | 7.5 | 0.5% | Aug 5, 2026 | In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoin... |
| CVE-2026-46581 | HIGH | 7.5 | 0.3% | Aug 5, 2026 | In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or ... |
| CVE-2026-18933 | HIGH | 7.2 | 0.4% | Aug 5, 2026 | The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-pri... |
| CVE-2026-71252 | HIGH | 8.2 | 0.4% | Aug 5, 2026 | toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands, ... |
| CVE-2026-71251 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download... |
| CVE-2026-71250 | MEDIUM | 4.3 | 0.2% | Aug 5, 2026 | Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters most private/reserved IPv4 ranges but contains an ex... |
| CVE-2026-71249 | MEDIUM | 6.1 | 0.2% | Aug 5, 2026 | 299Ko's public contact form (plugin/contact/controllers/ContactController.php, home) sets raw POST field values (name, f... |
| CVE-2026-71248 | CRITICAL | 9.8 | 0.3% | Aug 5, 2026 | Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw P... |
| CVE-2026-71247 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role t... |
| CVE-2026-71246 | MEDIUM | 4.3 | 0.2% | Aug 5, 2026 | Pixelfed's SearchController (behind the auth middleware) accepts a URL via its remote-search parameters and fetches it s... |
| CVE-2026-71245 | HIGH | 7.1 | 0.2% | Aug 5, 2026 | Mautic's getLeadIdsByFieldValueAction (LeadBundle/Controller/AjaxController.php) reads a field parameter from the reques... |
| CVE-2026-71244 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, r... |
| CVE-2026-71243 | HIGH | 8.8 | 0.4% | Aug 5, 2026 | The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, dest... |
| CVE-2026-71242 | HIGH | 8.3 | 0.2% | Aug 5, 2026 | Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership ... |
| CVE-2026-71241 | HIGH | 7.5 | 0.4% | Aug 5, 2026 | Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are mi... |
| CVE-2026-71240 | MEDIUM | 4.3 | 0.2% | Aug 5, 2026 | DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or sta... |
| CVE-2026-71239 | HIGH | 8.1 | 0.2% | Aug 5, 2026 | DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template const... |
| CVE-2026-71238 | CRITICAL | 9.1 | 0.3% | Aug 5, 2026 | DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from ... |
| CVE-2026-71237 | CRITICAL | 9.8 | 0.3% | Aug 5, 2026 | Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sa... |
| CVE-2026-71236 | HIGH | 8.7 | 0.2% | Aug 5, 2026 | Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incomi... |
