CVE Vulnerability Database
Search and browse 381,202 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-62323 | MEDIUM | 6.3 | 0.3% | Jul 31, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the se... |
| CVE-2026-55502 | HIGH | 7.1 | — | Jul 31, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin r... |
| CVE-2026-55499 | MEDIUM | 4.3 | 0.3% | Jul 31, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscri... |
| CVE-2026-55497 | MEDIUM | 6.5 | 0.5% | Jul 31, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image ... |
| CVE-2026-55496 | MEDIUM | 4.3 | — | Jul 31, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActi... |
| CVE-2026-55495 | MEDIUM | 4.3 | 0.4% | Jul 31, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-W... |
| CVE-2026-43833 | MEDIUM | 5.3 | 0.1% | Jul 31, 2026 | Full details and mitigation steps are currently restricted and will be published at a later date. |
| CVE-2026-43832 | HIGH | 7.5 | 0.1% | Jul 31, 2026 | Full details and mitigation steps are currently restricted and will be published at a later date. |
| CVE-2026-43831 | HIGH | 7.5 | 0.1% | Jul 31, 2026 | Full details and mitigation steps are currently restricted and will be published at a later date. |
| CVE-2026-43830 | CRITICAL | 9.8 | 0.1% | Jul 31, 2026 | Full details and mitigation steps are currently restricted and will be published at a later date. |
| CVE-2026-43829 | HIGH | 7.5 | 0.1% | Jul 31, 2026 | Full details and mitigation steps are currently restricted and will be published at a later date. |
| CVE-2026-6890 | — | — | — | Jul 31, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-6889 | — | — | — | Jul 31, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-18157 | HIGH | 7.8 | 0.2% | Jul 31, 2026 | A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit ... |
| CVE-2026-14541 | HIGH | 7.5 | 0.3% | Jul 31, 2026 | An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mc... |
| CVE-2026-14540 | MEDIUM | 6.1 | 0.2% | Jul 31, 2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-t... |
| CVE-2026-14539 | HIGH | 7.5 | 0.2% | Jul 31, 2026 | An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up ... |
| CVE-2026-14538 | HIGH | 7.7 | 0.2% | Jul 31, 2026 | An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Googl... |
| CVE-2026-14537 | CRITICAL | 9.8 | 0.2% | Jul 31, 2026 | Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0... |
| CVE-2026-58039 | LOW | 3.3 | 0.2% | Jul 31, 2026 | A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-wr... |
| CVE-2026-66720 | HIGH | 7.1 | 0.2% | Jul 30, 2026 | The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherTy... |
| CVE-2026-66421 | CRITICAL | 9.3 | 0.4% | Jul 30, 2026 | OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to ... |
| CVE-2026-66420 | HIGH | 8.8 | 0.2% | Jul 30, 2026 | MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated... |
| CVE-2026-66369 | HIGH | 7.1 | 0.2% | Jul 30, 2026 | The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-... |
| CVE-2026-66364 | HIGH | 7.1 | 0.2% | Jul 30, 2026 | The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 mu... |
