CVE Vulnerability Database

Search and browse 379,571 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-71283MEDIUM4.9Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), calls tarfile...
CVE-2026-71282MEDIUM6.5ChirpStack's SQLite-backend device tag filtering (chirpstack/src/storage/device.rs, in both get_count and list) interpol...
CVE-2026-71281HIGH8.8Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src...
CVE-2026-71280HIGH8.5go-shiori's DownloadBookmark (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Clien...
CVE-2026-71279HIGH8Zigbee2MQTT's ExternalJSExtension.getFilePath (lib/extension/externalJS.ts) joins a parameter received via an MQTT messa...
CVE-2026-71278CRITICAL9.8rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) cont...
CVE-2026-71277CRITICAL9.1rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP ...
CVE-2026-71276HIGH7.1Magistrala (formerly Mainflux)'s message-readers API reads a value from the HTTP query string (readers/api/http/transpor...
CVE-2026-71275MEDIUM5.4OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML r...
CVE-2026-71274HIGH8.5OpenBK7231T's CHANNEL_SetLabel (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel co...
CVE-2026-71273MEDIUM6.5OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request w...
CVE-2026-71272HIGH8.5Memos' webhook dispatch function safeDialContext (internal/webhook/webhook.go) resolves the target hostname via net.Defa...
CVE-2026-71271HIGH8.5Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP against a reservedCIDR...
CVE-2026-71270HIGH8.6Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanit...
CVE-2026-71269HIGH7.2Node-RED's local-filesystem library storage module (getLibraryEntry and saveLibraryEntry in packages/node_modules/@node-...
CVE-2026-71268CRITICAL9.9OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.s...
CVE-2026-71267CRITICAL9.8microtar's mtar_write_file_header and mtar_write_dir_header functions (src/microtar.c) copy a caller-supplied entry name...
CVE-2026-71266HIGH7.8tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl material file into a f...
CVE-2026-71265HIGH7.5Domoticz's MochadTCP::MatchLine handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data ...
CVE-2026-71264HIGH8.2WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson with no settings-PIN check, unlike ...
CVE-2026-71263CRITICAL9.1The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). Th...
CVE-2026-71262CRITICAL9.8IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (...
CVE-2026-71261HIGH7.8dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk metadata parsing. I...
CVE-2026-71260MEDIUM6.5ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (espho...
CVE-2026-71259HIGH8.6ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py...