CVE Vulnerability Database
Search and browse 381,217 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12945 | HIGH | 7.1 | 0.2% | Jul 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs throug... |
| CVE-2026-12940 | CRITICAL | 9.8 | 0.5% | Jul 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable ... |
| CVE-2026-12932 | HIGH | 8.1 | 0.4% | Jul 30, 2026 | A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 all... |
| CVE-2026-11885 | HIGH | 8.4 | — | Jul 30, 2026 | IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A careful... |
| CVE-2026-11771 | HIGH | 7.5 | 0.3% | Jul 30, 2026 | OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the... |
| CVE-2026-67596 | MEDIUM | 6.9 | — | Jul 30, 2026 | CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticate... |
| CVE-2026-58222 | HIGH | 8.8 | — | Jul 30, 2026 | A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Do... |
| CVE-2026-58216 | MEDIUM | 5.3 | 0.5% | Jul 30, 2026 | An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) servi... |
| CVE-2026-57862 | HIGH | 8.5 | — | Jul 30, 2026 | Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass... |
| CVE-2026-52680 | CRITICAL | 9.8 | 0.5% | Jul 30, 2026 | Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary... |
| CVE-2026-4978 | CRITICAL | 9.8 | — | Jul 30, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffi... |
| CVE-2026-48910 | MEDIUM | 6.5 | 0.3% | Jul 30, 2026 | A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the mar... |
| CVE-2026-44617 | MEDIUM | 6.5 | 0.4% | Jul 30, 2026 | LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constru... |
| CVE-2026-44616 | MEDIUM | 6.5 | 0.3% | Jul 30, 2026 | LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escap... |
| CVE-2026-44613 | MEDIUM | 6.1 | 0.4% | Jul 30, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin ... |
| CVE-2026-28814 | HIGH | 7.5 | 0.3% | Jul 30, 2026 | Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain s... |
| CVE-2026-28813 | HIGH | 8.8 | 0.1% | Jul 30, 2026 | Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommende... |
| CVE-2026-28812 | CRITICAL | 9.8 | 0.3% | Jul 30, 2026 | UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate pri... |
| CVE-2026-28811 | HIGH | 7.5 | 0.3% | Jul 30, 2026 | Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to ver... |
| CVE-2026-28323 | CRITICAL | 9.8 | 0.6% | Jul 30, 2026 | SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2... |
| CVE-2026-23985 | MEDIUM | 6.5 | 0.3% | Jul 30, 2026 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The... |
| CVE-2026-23981 | MEDIUM | 4.3 | 0.3% | Jul 30, 2026 | An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to upd... |
| CVE-2026-15658 | HIGH | 8.1 | 0.1% | Jul 30, 2026 | A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint t... |
| CVE-2026-15657 | MEDIUM | 6.5 | 0.1% | Jul 30, 2026 | A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor mercha... |
| CVE-2026-10842 | HIGH | 7.5 | 0.3% | Jul 30, 2026 | IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 T... |
