CVE Vulnerability Database
Search and browse 380,957 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-69096 | HIGH | 8.8 | 1.7% | Aug 3, 2026 | OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after... |
| CVE-2026-69095 | HIGH | 8.7 | — | Aug 3, 2026 | OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in ... |
| CVE-2026-69094 | MEDIUM | 5.3 | — | Aug 3, 2026 | Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_fu... |
| CVE-2026-69093 | HIGH | 7.1 | — | Aug 3, 2026 | Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs pe... |
| CVE-2026-69092 | MEDIUM | 6.9 | — | Aug 3, 2026 | Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echo... |
| CVE-2026-69091 | HIGH | 8.7 | — | Aug 3, 2026 | Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only ... |
| CVE-2026-69090 | MEDIUM | 6.9 | — | Aug 3, 2026 | Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role adm... |
| CVE-2026-69089 | HIGH | 8.7 | — | Aug 3, 2026 | Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image... |
| CVE-2026-69088 | HIGH | 8.6 | — | Aug 3, 2026 | Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint... |
| CVE-2026-69087 | HIGH | 7.1 | — | Aug 3, 2026 | The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, th... |
| CVE-2026-69086 | HIGH | 8.3 | — | Aug 3, 2026 | SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints,... |
| CVE-2026-69085 | CRITICAL | 10 | — | Aug 3, 2026 | SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-s... |
| CVE-2026-69084 | CRITICAL | 10 | — | Aug 3, 2026 | SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement... |
| CVE-2026-69083 | CRITICAL | 10 | — | Aug 3, 2026 | SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable... |
| CVE-2026-68587 | CRITICAL | 9.2 | — | Aug 3, 2026 | SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHea... |
| CVE-2026-68586 | CRITICAL | 9.2 | — | Aug 3, 2026 | SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints... |
| CVE-2026-68585 | MEDIUM | 6.9 | — | Aug 3, 2026 | SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that r... |
| CVE-2026-68584 | CRITICAL | 9.2 | — | Aug 3, 2026 | SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning end... |
| CVE-2026-67608 | HIGH | 8.6 | — | Aug 3, 2026 | Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injecti... |
| CVE-2026-64827 | CRITICAL | 9.8 | 0.4% | Aug 3, 2026 | Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication byp... |
| CVE-2026-18642 | HIGH | 7.8 | — | Aug 3, 2026 | Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock ... |
| CVE-2026-18601 | CRITICAL | 9.8 | 2.4% | Aug 3, 2026 | A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the fi... |
| CVE-2026-18600 | HIGH | 8.8 | 2.0% | Aug 3, 2026 | A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.s... |
| CVE-2026-18108 | CRITICAL | 9.8 | 0.2% | Aug 3, 2026 | Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an Encr... |
| CVE-2026-18092 | HIGH | 8.1 | 0.2% | Aug 3, 2026 | Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xm... |
