CVE Vulnerability Database
Search and browse 380,203 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71246 | MEDIUM | 4.3 | 0.2% | Aug 5, 2026 | Pixelfed's SearchController (behind the auth middleware) accepts a URL via its remote-search parameters and fetches it s... |
| CVE-2026-71245 | — | — | 0.2% | Aug 5, 2026 | Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid. |
| CVE-2026-71244 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, r... |
| CVE-2026-71243 | HIGH | 8.8 | 0.4% | Aug 5, 2026 | The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, dest... |
| CVE-2026-71242 | HIGH | 8.3 | 0.2% | Aug 5, 2026 | Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership ... |
| CVE-2026-71241 | HIGH | 7.5 | 0.4% | Aug 5, 2026 | Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are mi... |
| CVE-2026-71240 | MEDIUM | 4.3 | 0.2% | Aug 5, 2026 | DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or sta... |
| CVE-2026-71239 | HIGH | 8.1 | 0.2% | Aug 5, 2026 | DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template const... |
| CVE-2026-71238 | CRITICAL | 9.1 | 0.3% | Aug 5, 2026 | DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from ... |
| CVE-2026-71237 | CRITICAL | 9.8 | 0.3% | Aug 5, 2026 | Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sa... |
| CVE-2026-71236 | HIGH | 8.7 | 0.2% | Aug 5, 2026 | Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incomi... |
| CVE-2026-71235 | HIGH | 8.8 | 0.3% | Aug 5, 2026 | Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-sid... |
| CVE-2026-71234 | HIGH | 7.5 | 0.3% | Aug 5, 2026 | Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPubl... |
| CVE-2026-71233 | HIGH | 8.7 | 0.2% | Aug 5, 2026 | InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output... |
| CVE-2026-71232 | HIGH | 7.2 | 0.5% | Aug 5, 2026 | MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template ... |
| CVE-2026-71231 | CRITICAL | 9.8 | 0.3% | Aug 5, 2026 | IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decod... |
| CVE-2026-66747 | CRITICAL | 9.8 | — | Aug 5, 2026 | Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across ... |
| CVE-2026-60009 | HIGH | 8.8 | 0.3% | Aug 5, 2026 | In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every... |
| CVE-2026-17578 | LOW | 2.3 | — | Aug 5, 2026 | Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D re... |
| CVE-2026-14574 | MEDIUM | 6.5 | 0.1% | Aug 5, 2026 | In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` rec... |
| CVE-2026-14304 | MEDIUM | 5.5 | 0.1% | Aug 5, 2026 | In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and... |
| CVE-2026-12609 | HIGH | 7.5 | 0.4% | Aug 5, 2026 | In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlug... |
| CVE-2026-44945 | CRITICAL | 9.1 | 0.7% | Aug 5, 2026 | A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An... |
| CVE-2026-25703 | HIGH | 7.3 | — | Aug 5, 2026 | NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authenticatio... |
| CVE-2026-15452 | MEDIUM | 4.7 | 0.2% | Aug 5, 2026 | The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-Sit... |
