CVE Vulnerability Database
Search and browse 379,570 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54876 | HIGH | 7.5 | — | Aug 5, 2026 | Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by... |
| CVE-2026-17613 | HIGH | 7.5 | 0.4% | Aug 5, 2026 | Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated ... |
| CVE-2026-16102 | HIGH | 8.1 | 0.3% | Aug 5, 2026 | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solut... |
| CVE-2026-16100 | MEDIUM | 6.5 | 0.3% | Aug 5, 2026 | A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error... |
| CVE-2026-16071 | MEDIUM | 5.4 | 0.2% | Aug 5, 2026 | A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external direc... |
| CVE-2026-15573 | HIGH | 8.1 | 0.3% | Aug 5, 2026 | A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security ... |
| CVE-2026-12410 | HIGH | 7.8 | — | Aug 5, 2026 | Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-... |
| CVE-2026-7529 | HIGH | 7.5 | 0.4% | Aug 5, 2026 | The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and... |
| CVE-2026-7456 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec... |
| CVE-2026-67623 | HIGH | 8.8 | — | Aug 5, 2026 | Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary com... |
| CVE-2026-17506 | HIGH | 7.2 | 0.2% | Aug 5, 2026 | The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tr... |
| CVE-2026-16443 | CRITICAL | 9.1 | 0.1% | Aug 5, 2026 | A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine ... |
| CVE-2026-15979 | HIGH | 8.1 | 0.8% | Aug 5, 2026 | The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Del... |
| CVE-2025-70962 | HIGH | 7.5 | — | Aug 5, 2026 | Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials ... |
| CVE-2026-71294 | HIGH | 7.6 | 0.2% | Aug 5, 2026 | Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. ... |
| CVE-2026-71293 | MEDIUM | 6.2 | 0.2% | Aug 5, 2026 | Statamic CMS's user-augmentation resolver, AugmentedUser::get in src/Auth/AugmentedUser.php, contains an explicit case f... |
| CVE-2026-71292 | HIGH | 7.2 | 0.3% | Aug 5, 2026 | Subrion CMS's admin grid sorting helper, _gridGetSorting in includes/classes/ia.base.controller.admin.php, whitelists th... |
| CVE-2026-71291 | HIGH | 8.8 | 0.5% | Aug 5, 2026 | Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registe... |
| CVE-2026-71289 | CRITICAL | 9.8 | 0.4% | Aug 5, 2026 | The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publi... |
| CVE-2026-71288 | HIGH | 8.8 | 0.3% | Aug 5, 2026 | Koha's guided report builder (reports/guided_reports.pl) reads the CGI parameter and, for each value, a dynamically-name... |
| CVE-2026-71287 | HIGH | 8.8 | 0.3% | Aug 5, 2026 | Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . Because ... |
| CVE-2026-71286 | MEDIUM | 6.1 | 0.2% | Aug 5, 2026 | The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its property... |
| CVE-2026-71285 | HIGH | 8.1 | 0.2% | Aug 5, 2026 | Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo ... |
| CVE-2026-71284 | HIGH | 7.2 | 0.9% | Aug 5, 2026 | Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), takes the fir... |
| CVE-2026-71283 | MEDIUM | 4.9 | 0.3% | Aug 5, 2026 | Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), calls tarfile... |
