CVE Vulnerability Database
Search and browse 379,570 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-70599 | MEDIUM | 5.9 | — | Aug 5, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7,... |
| CVE-2026-70598 | LOW | 3.9 | — | Aug 5, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10... |
| CVE-2026-70597 | MEDIUM | 6.3 | — | Aug 5, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,... |
| CVE-2026-70596 | MEDIUM | 4.3 | — | Aug 5, 2026 | Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user ... |
| CVE-2026-70595 | MEDIUM | 4 | 0.2% | Aug 5, 2026 | Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, s... |
| CVE-2026-60053 | CRITICAL | 9.1 | 0.2% | Aug 5, 2026 | Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Admin... |
| CVE-2026-60023 | HIGH | 7.5 | 0.2% | Aug 5, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache An... |
| CVE-2026-53992 | MEDIUM | 6.1 | — | Aug 5, 2026 | ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php that allows remot... |
| CVE-2026-50749 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authentica... |
| CVE-2026-49331 | MEDIUM | 6.5 | 0.1% | Aug 5, 2026 | A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy for... |
| CVE-2026-48912 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ... |
| CVE-2026-48911 | HIGH | 7.5 | 0.2% | Aug 5, 2026 | Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: throug... |
| CVE-2026-48834 | HIGH | 7.5 | 0.2% | Aug 5, 2026 | Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: t... |
| CVE-2026-39924 | MEDIUM | 6.8 | — | Aug 5, 2026 | Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid sess... |
| CVE-2026-39923 | CRITICAL | 9.2 | — | Aug 5, 2026 | Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers t... |
| CVE-2026-32835 | — | — | — | Aug 5, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-18531 | MEDIUM | 5.3 | 0.4% | Aug 5, 2026 | IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use ... |
| CVE-2026-16442 | CRITICAL | 9.8 | 0.2% | Aug 5, 2026 | A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authenti... |
| CVE-2026-15656 | MEDIUM | 4.3 | 0.2% | Aug 5, 2026 | IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cook... |
| CVE-2026-15587 | CRITICAL | 9.4 | — | Aug 5, 2026 | Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows... |
| CVE-2026-15572 | HIGH | 8.8 | 0.3% | Aug 5, 2026 | A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mappe... |
| CVE-2026-13477 | HIGH | 8.8 | 0.2% | Aug 5, 2026 | IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privilege... |
| CVE-2026-12762 | MEDIUM | 5.3 | 0.2% | Aug 5, 2026 | IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensiti... |
| CVE-2026-12730 | LOW | 3.8 | 0.2% | Aug 5, 2026 | IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 throug... |
| CVE-2026-10025 | CRITICAL | 9.8 | 0.3% | Aug 5, 2026 | IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injec... |
