CVE Vulnerability Database
Search and browse 377,847 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-61514 | CRITICAL | 9.8 | — | Aug 4, 2026 | Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthent... |
| CVE-2026-18770 | HIGH | 7.3 | 0.3% | Aug 4, 2026 | A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an un... |
| CVE-2026-18766 | MEDIUM | 6.3 | 0.2% | Aug 4, 2026 | A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affect... |
| CVE-2026-18650 | HIGH | 8.8 | — | Aug 4, 2026 | Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MY... |
| CVE-2026-18401 | MEDIUM | 6.9 | — | Aug 4, 2026 | The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in S... |
| CVE-2026-11368 | MEDIUM | 6.5 | 0.2% | Aug 4, 2026 | The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning chann... |
| CVE-2026-70368 | MEDIUM | 6.5 | 0.4% | Aug 4, 2026 | A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log m... |
| CVE-2026-70367 | MEDIUM | 5.4 | 0.2% | Aug 4, 2026 | A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS pr... |
| CVE-2026-17070 | HIGH | 8.8 | — | Aug 4, 2026 | Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained b... |
| CVE-2026-14337 | MEDIUM | 4.6 | — | Aug 4, 2026 | Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a use... |
| CVE-2026-70373 | HIGH | 8.8 | 0.3% | Aug 4, 2026 | Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by conc... |
| CVE-2026-70372 | HIGH | 8.8 | 0.3% | Aug 4, 2026 | Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request pa... |
| CVE-2026-70371 | HIGH | 8.8 | 0.3% | Aug 4, 2026 | Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request ... |
| CVE-2026-70370 | HIGH | 8.8 | 0.3% | Aug 4, 2026 | Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Colu... |
| CVE-2026-70369 | HIGH | 8.8 | 0.3% | Aug 4, 2026 | Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-con... |
| CVE-2026-63252 | HIGH | 7.5 | 0.4% | Aug 4, 2026 | In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message ch... |
| CVE-2026-63248 | MEDIUM | 6.5 | 0.2% | Aug 4, 2026 | In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An an... |
| CVE-2026-62927 | HIGH | 7.5 | 0.4% | Aug 4, 2026 | In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space hand... |
| CVE-2026-61387 | HIGH | 7.5 | 0.3% | Aug 4, 2026 | In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fa... |
| CVE-2026-60007 | HIGH | 7.4 | 0.5% | Aug 4, 2026 | In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA P... |
| CVE-2026-58080 | HIGH | 8.2 | 0.4% | Aug 4, 2026 | In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On... |
| CVE-2026-18809 | MEDIUM | 6.5 | — | Aug 4, 2026 | Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153... |
| CVE-2026-18806 | HIGH | 7.1 | 0.1% | Aug 4, 2026 | External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-im... |
| CVE-2026-10710 | HIGH | 7.8 | — | Aug 4, 2026 | A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerab... |
| CVE-2026-10709 | HIGH | 7.8 | — | Aug 4, 2026 | A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerab... |
