CVE Vulnerability Database
Search and browse 380,660 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-17578 | LOW | 2.3 | — | Aug 5, 2026 | Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D re... |
| CVE-2026-14574 | MEDIUM | 6.5 | 0.1% | Aug 5, 2026 | In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` rec... |
| CVE-2026-14304 | MEDIUM | 5.5 | 0.1% | Aug 5, 2026 | In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and... |
| CVE-2026-12609 | HIGH | 7.5 | 0.4% | Aug 5, 2026 | In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlug... |
| CVE-2026-44945 | CRITICAL | 9.1 | 0.7% | Aug 5, 2026 | A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An... |
| CVE-2026-25703 | HIGH | 7.3 | — | Aug 5, 2026 | NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authenticatio... |
| CVE-2026-15452 | MEDIUM | 4.7 | 0.2% | Aug 5, 2026 | The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-Sit... |
| CVE-2026-0931 | MEDIUM | 6.9 | — | Aug 5, 2026 | Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cau... |
| CVE-2026-8029 | LOW | 3.9 | — | Aug 5, 2026 | The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements ... |
| CVE-2026-10090 | CRITICAL | 9 | 0.2% | Aug 5, 2026 | A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cl... |
| CVE-2026-10059 | CRITICAL | 9.1 | 0.3% | Aug 5, 2026 | A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namesp... |
| CVE-2026-7726 | MEDIUM | 6.5 | 0.3% | Aug 5, 2026 | The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on... |
| CVE-2026-7693 | HIGH | 7.2 | 2.2% | Aug 5, 2026 | The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.... |
| CVE-2026-7520 | HIGH | 8.1 | 0.3% | Aug 5, 2026 | The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missin... |
| CVE-2026-7444 | HIGH | 8.1 | 0.2% | Aug 5, 2026 | The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2026-7441 | MEDIUM | 6.4 | 0.2% | Aug 5, 2026 | The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute... |
| CVE-2026-7105 | MEDIUM | 4.3 | 0.2% | Aug 5, 2026 | The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on... |
| CVE-2026-71215 | HIGH | 7.5 | 0.4% | Aug 5, 2026 | art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include and ext... |
| CVE-2026-71214 | CRITICAL | 9.8 | 0.3% | Aug 5, 2026 | The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasur... |
| CVE-2026-71213 | CRITICAL | 9.1 | 0.4% | Aug 5, 2026 | Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting,... |
| CVE-2026-71212 | MEDIUM | 4.4 | 0.1% | Aug 5, 2026 | xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py... |
| CVE-2026-71211 | HIGH | 7.1 | 0.2% | Aug 5, 2026 | MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _cr... |
| CVE-2026-71210 | MEDIUM | 5.3 | 0.2% | Aug 5, 2026 | Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the r... |
| CVE-2026-71209 | HIGH | 7.5 | 0.7% | Aug 5, 2026 | audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes agai... |
| CVE-2026-71208 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cl... |
