CVE Vulnerability Database
Search and browse 377,822 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63455 | CRITICAL | 9.8 | 0.4% | Aug 4, 2026 | Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated ... |
| CVE-2026-58075 | HIGH | 8.7 | — | Aug 4, 2026 | A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leverag... |
| CVE-2026-58074 | HIGH | 8.6 | — | Aug 4, 2026 | A vulnerability allowing a high-privileged user to execute arbitrary code on the server. |
| CVE-2026-58073 | CRITICAL | 9.5 | — | Aug 4, 2026 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent an... |
| CVE-2026-58072 | CRITICAL | 9 | — | Aug 4, 2026 | A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead... |
| CVE-2026-58071 | HIGH | 8.2 | — | Aug 4, 2026 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance A... |
| CVE-2026-58067 | HIGH | 8.7 | — | Aug 4, 2026 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause ... |
| CVE-2026-56848 | HIGH | 7.5 | — | Aug 4, 2026 | A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_m... |
| CVE-2026-48121 | MEDIUM | 6.7 | — | Aug 4, 2026 | @langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for sto... |
| CVE-2026-18787 | HIGH | 8.8 | 1.7% | Aug 4, 2026 | A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the fi... |
| CVE-2026-18785 | MEDIUM | 5.3 | 0.1% | Aug 4, 2026 | A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Cli... |
| CVE-2026-18784 | MEDIUM | 5.3 | 0.1% | Aug 4, 2026 | A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute ... |
| CVE-2026-18775 | MEDIUM | 6.3 | 0.3% | Aug 4, 2026 | A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browse... |
| CVE-2026-18774 | MEDIUM | 6.3 | 0.2% | Aug 4, 2026 | A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file ag... |
| CVE-2026-15920 | MEDIUM | 6.1 | 0.3% | Aug 4, 2026 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field(... |
| CVE-2026-15830 | MEDIUM | 6.9 | 0.5% | Aug 4, 2026 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome... |
| CVE-2026-15337 | MEDIUM | 6.9 | 0.5% | Aug 4, 2026 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()... |
| CVE-2026-15314 | HIGH | 7.5 | 0.2% | Aug 4, 2026 | Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HT... |
| CVE-2026-15307 | HIGH | 8.8 | 0.5% | Aug 4, 2026 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse... |
| CVE-2025-29296 | CRITICAL | 9.8 | — | Aug 4, 2026 | H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V... |
| CVE-2026-69254 | CRITICAL | 9.4 | — | Aug 4, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScri... |
| CVE-2026-69253 | CRITICAL | 9 | 0.3% | Aug 4, 2026 | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1... |
| CVE-2026-69252 | HIGH | 7.2 | — | Aug 4, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/fil... |
| CVE-2026-69110 | CRITICAL | 9.3 | — | Aug 4, 2026 | OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attacker... |
| CVE-2026-69100 | HIGH | 8.8 | — | Aug 4, 2026 | LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability i... |
