CVE Vulnerability Database
Search and browse 381,206 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-66421 | CRITICAL | 9.3 | 0.4% | Jul 30, 2026 | OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to ... |
| CVE-2026-66420 | HIGH | 8.8 | 0.2% | Jul 30, 2026 | MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated... |
| CVE-2026-66369 | HIGH | 7.1 | 0.2% | Jul 30, 2026 | The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-... |
| CVE-2026-66364 | HIGH | 7.1 | 0.2% | Jul 30, 2026 | The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 mu... |
| CVE-2026-66360 | HIGH | 8.7 | 0.3% | Jul 30, 2026 | The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A mis... |
| CVE-2026-66349 | MEDIUM | 6.9 | 0.2% | Jul 30, 2026 | The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed ... |
| CVE-2026-65423 | HIGH | 8.8 | 0.6% | Jul 30, 2026 | An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to t... |
| CVE-2026-65421 | HIGH | 7.1 | 0.2% | Jul 30, 2026 | The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length v... |
| CVE-2026-63550 | HIGH | 7.1 | 0.2% | Jul 30, 2026 | The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request mess... |
| CVE-2026-63362 | HIGH | 8.2 | 1.5% | Jul 30, 2026 | An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cau... |
| CVE-2026-63035 | HIGH | 8.1 | 0.6% | Jul 30, 2026 | A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attack... |
| CVE-2026-63033 | MEDIUM | 6.9 | 0.3% | Jul 30, 2026 | A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationO... |
| CVE-2026-61893 | MEDIUM | 6.9 | 0.3% | Jul 30, 2026 | A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBu... |
| CVE-2026-56758 | MEDIUM | 6.9 | 0.2% | Jul 30, 2026 | The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain... |
| CVE-2026-10031 | MEDIUM | 4.2 | 0.2% | Jul 30, 2026 | SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-direc... |
| CVE-2026-68563 | MEDIUM | 5.5 | 0.1% | Jul 30, 2026 | A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and th... |
| CVE-2026-68562 | MEDIUM | 6.2 | 0.2% | Jul 30, 2026 | A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp ... |
| CVE-2026-64816 | HIGH | 7.1 | — | Jul 30, 2026 | RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_proce... |
| CVE-2026-63559 | HIGH | 8.7 | 0.4% | Jul 30, 2026 | An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to r... |
| CVE-2026-62845 | MEDIUM | 4.7 | — | Jul 30, 2026 | Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore driv... |
| CVE-2026-62246 | HIGH | 8.5 | 0.3% | Jul 30, 2026 | Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane dat... |
| CVE-2026-5846 | HIGH | 7.6 | 0.2% | Jul 30, 2026 | The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 cert... |
| CVE-2026-38709 | CRITICAL | 9.8 | — | Jul 30, 2026 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2... |
| CVE-2026-18064 | HIGH | 8.2 | 0.3% | Jul 30, 2026 | An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a s... |
| CVE-2026-12562 | HIGH | 8.8 | 0.3% | Jul 30, 2026 | The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full... |
