CVE Vulnerability Database
Search and browse 378,517 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18243 | MEDIUM | 6.9 | — | Aug 3, 2026 | Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticat... |
| CVE-2026-18651 | MEDIUM | 5.4 | 0.2% | Aug 3, 2026 | A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind cr... |
| CVE-2026-18568 | HIGH | 7.5 | 0.2% | Aug 3, 2026 | XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when ev... |
| CVE-2026-18508 | MEDIUM | 4.4 | 0.1% | Aug 3, 2026 | A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confin... |
| CVE-2026-18248 | CRITICAL | 9.1 | — | Aug 3, 2026 | @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.cont... |
| CVE-2026-15430 | MEDIUM | 6.2 | — | Aug 3, 2026 | Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, ... |
| CVE-2026-67609 | HIGH | 8.5 | — | Aug 3, 2026 | Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalatio... |
| CVE-2026-9487 | CRITICAL | 9.1 | 0.2% | Aug 3, 2026 | XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, ... |
| CVE-2026-9390 | CRITICAL | 9.1 | 0.3% | Aug 3, 2026 | XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Si... |
| CVE-2026-69097 | HIGH | 7.3 | 0.2% | Aug 3, 2026 | GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitra... |
| CVE-2026-69096 | HIGH | 8.8 | 1.7% | Aug 3, 2026 | OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after... |
| CVE-2026-69095 | HIGH | 8.7 | — | Aug 3, 2026 | OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in ... |
| CVE-2026-69094 | MEDIUM | 5.3 | — | Aug 3, 2026 | Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_fu... |
| CVE-2026-69093 | HIGH | 7.1 | — | Aug 3, 2026 | Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs pe... |
| CVE-2026-69092 | MEDIUM | 6.9 | — | Aug 3, 2026 | Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echo... |
| CVE-2026-69091 | HIGH | 8.7 | — | Aug 3, 2026 | Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only ... |
| CVE-2026-69090 | MEDIUM | 6.9 | — | Aug 3, 2026 | Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role adm... |
| CVE-2026-69089 | HIGH | 8.7 | — | Aug 3, 2026 | Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image... |
| CVE-2026-69088 | HIGH | 8.6 | — | Aug 3, 2026 | Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint... |
| CVE-2026-69087 | HIGH | 7.1 | — | Aug 3, 2026 | The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, th... |
| CVE-2026-69086 | HIGH | 8.3 | — | Aug 3, 2026 | SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints,... |
| CVE-2026-69085 | CRITICAL | 10 | — | Aug 3, 2026 | SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-s... |
| CVE-2026-69084 | CRITICAL | 10 | — | Aug 3, 2026 | SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement... |
| CVE-2026-69083 | CRITICAL | 10 | — | Aug 3, 2026 | SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable... |
| CVE-2026-68587 | CRITICAL | 9.2 | — | Aug 3, 2026 | SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHea... |
