CVE Vulnerability Database
Search and browse 377,926 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11366 | LOW | 3.7 | 0.1% | Aug 4, 2026 | The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthentica... |
| CVE-2026-10526 | MEDIUM | 5.8 | 0.1% | Aug 4, 2026 | The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests th... |
| CVE-2026-68744 | LOW | 3.3 | — | Aug 4, 2026 | A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for... |
| CVE-2026-18739 | LOW | 2.5 | 0.1% | Aug 4, 2026 | A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when... |
| CVE-2026-18569 | LOW | 3.7 | 0.2% | Aug 4, 2026 | A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Bui... |
| CVE-2026-16881 | HIGH | 8.7 | 0.3% | Aug 4, 2026 | A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component... |
| CVE-2026-42169 | HIGH | 7.3 | 0.1% | Aug 4, 2026 | A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `f... |
| CVE-2026-18723 | MEDIUM | 6.3 | 0.2% | Aug 4, 2026 | A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file... |
| CVE-2026-18722 | MEDIUM | 6.3 | 0.2% | Aug 4, 2026 | A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurv... |
| CVE-2026-18721 | MEDIUM | 4.3 | 0.3% | Aug 4, 2026 | A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown processing of the file... |
| CVE-2026-14818 | HIGH | 7.2 | 0.4% | Aug 4, 2026 | A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versi... |
| CVE-2026-8508 | MEDIUM | 6.5 | 0.5% | Aug 4, 2026 | An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions throug... |
| CVE-2026-6837 | HIGH | 7.2 | 0.9% | Aug 4, 2026 | A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions... |
| CVE-2026-18720 | MEDIUM | 5.5 | 0.3% | Aug 4, 2026 | A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?... |
| CVE-2026-18719 | MEDIUM | 6.3 | 0.2% | Aug 4, 2026 | A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2html.py of the compo... |
| CVE-2026-58045 | MEDIUM | 6.2 | — | Aug 4, 2026 | A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:z... |
| CVE-2026-58044 | LOW | 3.7 | — | Aug 4, 2026 | A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild ou... |
| CVE-2026-58042 | MEDIUM | 5.9 | — | Aug 4, 2026 | A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Rec... |
| CVE-2026-58041 | MEDIUM | 5.3 | — | Aug 4, 2026 | A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to cont... |
| CVE-2026-56846 | HIGH | 7.5 | — | Aug 4, 2026 | A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memor... |
| CVE-2026-56845 | HIGH | 7.5 | — | Aug 4, 2026 | An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configur... |
| CVE-2026-66326 | HIGH | 8.8 | 0.7% | Aug 4, 2026 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-66325 | MEDIUM | 6.1 | 0.4% | Aug 4, 2026 | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofin... |
| CVE-2026-66322 | MEDIUM | 5.4 | 0.3% | Aug 4, 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne... |
| CVE-2026-66321 | CRITICAL | 9.6 | 0.9% | Aug 4, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ... |
