CVE Vulnerability Database
Search and browse 380,858 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-70370 | HIGH | 8.8 | 0.3% | Aug 4, 2026 | Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Colu... |
| CVE-2026-70369 | HIGH | 8.8 | 0.3% | Aug 4, 2026 | Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-con... |
| CVE-2026-63252 | HIGH | 7.5 | 0.4% | Aug 4, 2026 | In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message ch... |
| CVE-2026-63248 | MEDIUM | 6.5 | 0.2% | Aug 4, 2026 | In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An an... |
| CVE-2026-62927 | HIGH | 7.5 | 0.4% | Aug 4, 2026 | In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space hand... |
| CVE-2026-61387 | HIGH | 7.5 | 0.3% | Aug 4, 2026 | In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fa... |
| CVE-2026-60007 | HIGH | 7.4 | 0.5% | Aug 4, 2026 | In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA P... |
| CVE-2026-58080 | HIGH | 8.2 | 0.4% | Aug 4, 2026 | In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On... |
| CVE-2026-18809 | MEDIUM | 6.5 | 0.2% | Aug 4, 2026 | Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153... |
| CVE-2026-18806 | HIGH | 7.1 | 0.1% | Aug 4, 2026 | External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-im... |
| CVE-2026-10710 | HIGH | 7.8 | — | Aug 4, 2026 | A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerab... |
| CVE-2026-10709 | HIGH | 7.8 | — | Aug 4, 2026 | A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerab... |
| CVE-2026-66884 | LOW | 2.1 | — | Aug 4, 2026 | Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback mod... |
| CVE-2026-66883 | MEDIUM | 6.3 | — | Aug 4, 2026 | Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize modu... |
| CVE-2026-10050 | CRITICAL | 9.1 | 0.4% | Aug 4, 2026 | In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. Th... |
| CVE-2026-18772 | MEDIUM | 6.5 | 0.3% | Aug 4, 2026 | Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data ... |
| CVE-2026-15721 | CRITICAL | 9.8 | — | Aug 4, 2026 | Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Dig... |
| CVE-2026-14838 | HIGH | 7.4 | — | Aug 4, 2026 | Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. ... |
| CVE-2026-14804 | CRITICAL | 9.1 | — | Aug 4, 2026 | Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Hu... |
| CVE-2026-14465 | MEDIUM | 6.5 | — | Aug 4, 2026 | Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human ... |
| CVE-2026-14219 | MEDIUM | 5.4 | — | Aug 4, 2026 | URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUM... |
| CVE-2026-14202 | MEDIUM | 5.3 | — | Aug 4, 2026 | Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human ... |
| CVE-2026-14194 | MEDIUM | 6.5 | — | Aug 4, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Infor... |
| CVE-2026-14192 | MEDIUM | 5.4 | — | Aug 4, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and... |
| CVE-2026-14175 | CRITICAL | 9.8 | — | Aug 4, 2026 | Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIS... |
