CVE Vulnerability Database
Search and browse 377,747 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18854 | HIGH | 7.3 | 0.3% | Aug 5, 2026 | A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element ... |
| CVE-2026-18853 | MEDIUM | 5.3 | 0.2% | Aug 5, 2026 | A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the fu... |
| CVE-2026-18852 | LOW | 3.3 | 0.1% | Aug 5, 2026 | A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This imp... |
| CVE-2026-18103 | MEDIUM | 4.9 | 0.4% | Aug 5, 2026 | A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Program... |
| CVE-2026-45537 | CRITICAL | 9.1 | 0.4% | Aug 4, 2026 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the con... |
| CVE-2026-18819 | MEDIUM | 4.3 | 0.2% | Aug 4, 2026 | A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vul... |
| CVE-2026-18818 | MEDIUM | 6.3 | 0.2% | Aug 4, 2026 | A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView o... |
| CVE-2026-70620 | MEDIUM | 6.8 | 0.3% | Aug 4, 2026 | Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attacke... |
| CVE-2026-70619 | HIGH | 8.8 | 0.4% | Aug 4, 2026 | Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users ... |
| CVE-2026-70594 | MEDIUM | 6.7 | 0.2% | Aug 4, 2026 | Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions ... |
| CVE-2026-70593 | MEDIUM | 6.6 | 0.3% | Aug 4, 2026 | Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff... |
| CVE-2026-70592 | MEDIUM | 5.5 | 0.3% | Aug 4, 2026 | Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overw... |
| CVE-2026-70591 | MEDIUM | 4.1 | 0.2% | Aug 4, 2026 | Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin ima... |
| CVE-2026-70590 | MEDIUM | 4.8 | 0.2% | Aug 4, 2026 | Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed password... |
| CVE-2026-70589 | MEDIUM | 4.8 | 0.2% | Aug 4, 2026 | Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to rede... |
| CVE-2026-67862 | HIGH | 7.5 | 0.2% | Aug 4, 2026 | open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c... |
| CVE-2026-67861 | HIGH | 7.5 | 0.4% | Aug 4, 2026 | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemo... |
| CVE-2026-67860 | HIGH | 7.5 | 0.1% | Aug 4, 2026 | open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database ... |
| CVE-2026-67859 | HIGH | 7.5 | 0.5% | Aug 4, 2026 | Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discover... |
| CVE-2026-67858 | HIGH | 7.5 | 0.5% | Aug 4, 2026 | Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast di... |
| CVE-2026-67857 | HIGH | 7.5 | 0.4% | Aug 4, 2026 | open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/u... |
| CVE-2026-67856 | HIGH | 7.5 | 0.2% | Aug 4, 2026 | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscri... |
| CVE-2026-67855 | HIGH | 7.5 | 0.2% | Aug 4, 2026 | open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMA... |
| CVE-2026-52370 | MEDIUM | 6.1 | 0.2% | Aug 4, 2026 | A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execu... |
| CVE-2026-51144 | MEDIUM | 6.1 | 0.2% | Aug 4, 2026 | Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker ... |
