CVE Vulnerability Database
Search and browse 381,619 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54661 | HIGH | 8.3 | 0.3% | Jul 29, 2026 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templat... |
| CVE-2026-54660 | HIGH | 7.4 | 0.2% | Jul 29, 2026 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol... |
| CVE-2026-12703 | HIGH | 8 | 0.2% | Jul 29, 2026 | TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenti... |
| CVE-2026-9177 | CRITICAL | 9.4 | 0.3% | Jul 29, 2026 | A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway Se... |
| CVE-2026-67217 | MEDIUM | 6.9 | 0.2% | Jul 29, 2026 | cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a repl... |
| CVE-2026-67216 | HIGH | 7.5 | 0.3% | Jul 29, 2026 | cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the... |
| CVE-2026-67215 | HIGH | 8.7 | 0.3% | Jul 29, 2026 | cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON... |
| CVE-2026-67214 | HIGH | 7.5 | 0.3% | Jul 29, 2026 | nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its no... |
| CVE-2026-67213 | HIGH | 7.5 | 0.3% | Jul 29, 2026 | nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these fun... |
| CVE-2026-66490 | MEDIUM | 6.1 | 0.2% | Jul 29, 2026 | Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2 |
| CVE-2026-66489 | MEDIUM | 5.3 | 0.2% | Jul 29, 2026 | Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2 |
| CVE-2026-66488 | MEDIUM | 5.3 | 0.2% | Jul 29, 2026 | Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2 |
| CVE-2026-66400 | MEDIUM | 6.3 | 0.2% | Jul 29, 2026 | Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php wh... |
| CVE-2026-65890 | CRITICAL | 9.8 | 0.2% | Jul 29, 2026 | Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthe... |
| CVE-2026-65889 | HIGH | 7.5 | 0.3% | Jul 29, 2026 | Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allow... |
| CVE-2026-55995 | HIGH | 8.7 | 0.3% | Jul 29, 2026 | A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects... |
| CVE-2026-18174 | MEDIUM | 5.3 | 0.2% | Jul 29, 2026 | @fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0.2, when the header ... |
| CVE-2026-16751 | MEDIUM | 6.5 | 0.2% | Jul 29, 2026 | Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an auth... |
| CVE-2026-65946 | MEDIUM | 6.1 | 0.1% | Jul 29, 2026 | Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0 |
| CVE-2026-65944 | HIGH | 8.8 | 0.1% | Jul 29, 2026 | Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0 |
| CVE-2026-65943 | HIGH | 7.5 | 0.2% | Jul 29, 2026 | Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0 |
| CVE-2026-65891 | MEDIUM | 6.5 | 0.2% | Jul 29, 2026 | Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function ... |
| CVE-2026-65885 | HIGH | 8.8 | 0.3% | Jul 29, 2026 | Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows au... |
| CVE-2026-65884 | CRITICAL | 9.8 | 0.2% | Jul 29, 2026 | Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provide... |
| CVE-2026-50641 | HIGH | 7.1 | 0.2% | Jul 29, 2026 | Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in... |
