CVE Vulnerability Database
Search and browse 378,068 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48031 | CRITICAL | 9.1 | — | Aug 3, 2026 | go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 202... |
| CVE-2026-47211 | HIGH | 8.4 | — | Aug 3, 2026 | Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to ... |
| CVE-2026-18655 | HIGH | 7.1 | 0.3% | Aug 3, 2026 | Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.... |
| CVE-2026-18654 | MEDIUM | 6.9 | 0.3% | Aug 3, 2026 | Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v... |
| CVE-2026-18644 | MEDIUM | 5.4 | 0.4% | Aug 3, 2026 | A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /... |
| CVE-2026-18641 | HIGH | 7.3 | 1.7% | Aug 3, 2026 | A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by... |
| CVE-2026-18632 | MEDIUM | 6.3 | 0.4% | Aug 3, 2026 | A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of ... |
| CVE-2026-18631 | MEDIUM | 6.3 | 0.4% | Aug 3, 2026 | A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig ... |
| CVE-2026-59913 | HIGH | 7.8 | 0.1% | Aug 3, 2026 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Criti... |
| CVE-2026-59912 | HIGH | 7.8 | 0.1% | Aug 3, 2026 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnera... |
| CVE-2026-38447 | CRITICAL | 9.8 | — | Aug 3, 2026 | osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with ... |
| CVE-2026-38446 | MEDIUM | 6.1 | — | Aug 3, 2026 | A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread e... |
| CVE-2026-38444 | MEDIUM | 6.1 | — | Aug 3, 2026 | osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is... |
| CVE-2026-18616 | CRITICAL | 9.8 | 2.0% | Aug 3, 2026 | A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of... |
| CVE-2026-18615 | CRITICAL | 9.8 | 2.0% | Aug 3, 2026 | A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate... |
| CVE-2026-18614 | CRITICAL | 9.8 | 2.0% | Aug 3, 2026 | A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file ... |
| CVE-2025-15631 | MEDIUM | 5.9 | 0.1% | Aug 3, 2026 | A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing al... |
| CVE-2025-15630 | MEDIUM | 5.9 | 0.2% | Aug 3, 2026 | A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with t... |
| CVE-2025-15629 | HIGH | 7.5 | 0.1% | Aug 3, 2026 | A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communicati... |
| CVE-2025-15628 | HIGH | 7.5 | 0.1% | Aug 3, 2026 | Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between contr... |
| CVE-2025-15627 | HIGH | 7.5 | 0.2% | Aug 3, 2026 | A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to... |
| CVE-2025-15544 | MEDIUM | 5.9 | 0.1% | Aug 3, 2026 | A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials assoc... |
| CVE-2026-61524 | HIGH | 8.6 | — | Aug 3, 2026 | WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature th... |
| CVE-2026-61523 | HIGH | 8.6 | — | Aug 3, 2026 | WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated... |
| CVE-2026-40717 | HIGH | 7.8 | 0.1% | Aug 3, 2026 | Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnera... |
