CVE Vulnerability Database
Search and browse 378,063 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48115 | MEDIUM | 6.3 | 0.2% | Aug 3, 2026 | Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but... |
| CVE-2026-47746 | HIGH | 8.9 | 0.2% | Aug 3, 2026 | Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, are vulne... |
| CVE-2026-46714 | MEDIUM | 5.1 | 0.3% | Aug 3, 2026 | Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to 2026.5.4, contain a... |
| CVE-2026-46713 | CRITICAL | 9.2 | 0.2% | Aug 3, 2026 | Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a... |
| CVE-2026-46712 | LOW | 2.3 | 0.2% | Aug 3, 2026 | Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior to 2026.5.4, contain ... |
| CVE-2026-18682 | LOW | 3.1 | 0.2% | Aug 3, 2026 | A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /api... |
| CVE-2026-10849 | HIGH | 7.5 | 0.3% | Aug 3, 2026 | The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update ser... |
| CVE-2026-69246 | HIGH | 7.2 | 0.2% | Aug 3, 2026 | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and... |
| CVE-2026-69245 | MEDIUM | 6.5 | — | Aug 3, 2026 | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of ... |
| CVE-2026-69244 | HIGH | 7.1 | 0.3% | Aug 3, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap r... |
| CVE-2026-69243 | MEDIUM | 6.3 | 0.3% | Aug 3, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were v... |
| CVE-2026-69240 | CRITICAL | 9.8 | 0.3% | Aug 3, 2026 | Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracl... |
| CVE-2026-67976 | HIGH | 7.5 | 0.1% | Aug 3, 2026 | The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allo... |
| CVE-2026-67972 | HIGH | 7.5 | 0.1% | Aug 3, 2026 | An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data... |
| CVE-2026-66065 | HIGH | 8.4 | 0.3% | Aug 3, 2026 | Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to ... |
| CVE-2026-52521 | HIGH | 8.1 | 0.1% | Aug 3, 2026 | A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via th... |
| CVE-2026-52520 | MEDIUM | 5.4 | 0.2% | Aug 3, 2026 | Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/... |
| CVE-2026-52102 | CRITICAL | 9.8 | 0.6% | Aug 3, 2026 | An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to exe... |
| CVE-2026-51775 | CRITICAL | 9.8 | 0.1% | Aug 3, 2026 | SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the applicati... |
| CVE-2026-51190 | CRITICAL | 9.8 | 0.5% | Aug 3, 2026 | The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spaw... |
| CVE-2026-49132 | MEDIUM | 5.4 | 0.1% | Aug 3, 2026 | OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to injec... |
| CVE-2026-49131 | MEDIUM | 5.4 | 0.2% | Aug 3, 2026 | OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with fir... |
| CVE-2026-48113 | HIGH | 8.5 | 0.2% | Aug 3, 2026 | Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated client... |
| CVE-2026-48063 | CRITICAL | 9.3 | 0.2% | Aug 3, 2026 | Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baile... |
| CVE-2026-48061 | MEDIUM | 5.9 | — | Aug 3, 2026 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypa... |
