CVE Vulnerability Database
Search and browse 378,066 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48113 | HIGH | 8.5 | 0.2% | Aug 3, 2026 | Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated client... |
| CVE-2026-48063 | CRITICAL | 9.3 | 0.2% | Aug 3, 2026 | Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baile... |
| CVE-2026-48061 | MEDIUM | 5.9 | — | Aug 3, 2026 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypa... |
| CVE-2026-41447 | HIGH | 8.5 | 0.1% | Aug 3, 2026 | FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbit... |
| CVE-2026-18738 | MEDIUM | 4.7 | — | Aug 3, 2026 | Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote att... |
| CVE-2026-18737 | HIGH | 7.1 | 0.2% | Aug 3, 2026 | Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL... |
| CVE-2026-18736 | MEDIUM | 5.3 | — | Aug 3, 2026 | Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the serve... |
| CVE-2026-18733 | HIGH | 8.8 | 0.3% | Aug 3, 2026 | A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors... |
| CVE-2026-18648 | MEDIUM | 5.3 | 0.2% | Aug 3, 2026 | A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDat... |
| CVE-2026-18647 | HIGH | 7.3 | 0.4% | Aug 3, 2026 | A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue ... |
| CVE-2026-18646 | MEDIUM | 5.5 | 0.5% | Aug 3, 2026 | A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system... |
| CVE-2026-18645 | MEDIUM | 5.4 | 0.4% | Aug 3, 2026 | A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /sys... |
| CVE-2026-69198 | MEDIUM | 6.9 | 0.3% | Aug 3, 2026 | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, ev... |
| CVE-2026-69192 | HIGH | 7.7 | 0.3% | Aug 3, 2026 | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 ac... |
| CVE-2026-69185 | HIGH | 7.5 | — | Aug 3, 2026 | Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a sp... |
| CVE-2026-68981 | HIGH | 7.5 | 0.3% | Aug 3, 2026 | Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding... |
| CVE-2026-68980 | CRITICAL | 9.1 | 0.3% | Aug 3, 2026 | Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts throu... |
| CVE-2026-68979 | CRITICAL | 9.8 | 0.4% | Aug 3, 2026 | Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization... |
| CVE-2026-67599 | HIGH | 8.6 | 1.9% | Aug 3, 2026 | ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attacke... |
| CVE-2026-67598 | CRITICAL | 9.1 | — | Aug 3, 2026 | Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that all... |
| CVE-2026-66296 | MEDIUM | 6.1 | 0.3% | Aug 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-sit... |
| CVE-2026-62354 | MEDIUM | 4.3 | 0.3% | Aug 3, 2026 | Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients wit... |
| CVE-2026-58139 | MEDIUM | 6.5 | — | Aug 3, 2026 | The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with S... |
| CVE-2026-48031 | CRITICAL | 9.1 | — | Aug 3, 2026 | go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 202... |
| CVE-2026-47211 | HIGH | 8.4 | — | Aug 3, 2026 | Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to ... |
