CVE Vulnerability Database
Search and browse 383,840 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54081 | MEDIUM | 6.9 | 0.3% | Jul 29, 2026 | veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service... |
| CVE-2026-54080 | MEDIUM | 6.9 | 0.3% | Jul 29, 2026 | veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service... |
| CVE-2026-54079 | HIGH | 8.7 | 0.3% | Jul 29, 2026 | veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30... |
| CVE-2026-54078 | HIGH | 8.7 | 0.3% | Jul 29, 2026 | veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, ve... |
| CVE-2026-50558 | MEDIUM | 5.9 | — | Jul 29, 2026 | Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix d... |
| CVE-2026-17550 | MEDIUM | 5.5 | 0.1% | Jul 29, 2026 | A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerabili... |
| CVE-2026-16543 | HIGH | 7.1 | — | Jul 29, 2026 | Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation pr... |
| CVE-2026-16465 | HIGH | 7.1 | 0.1% | Jul 29, 2026 | A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerabili... |
| CVE-2026-16463 | HIGH | 7.8 | 0.2% | Jul 29, 2026 | A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A m... |
| CVE-2026-15228 | HIGH | 7.1 | — | Jul 29, 2026 | Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a clust... |
| CVE-2026-66724 | MEDIUM | 5.3 | 0.3% | Jul 29, 2026 | MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob u... |
| CVE-2026-66723 | HIGH | 7 | 0.5% | Jul 29, 2026 | MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. ... |
| CVE-2026-65947 | HIGH | 7.3 | 0.1% | Jul 29, 2026 | Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2 |
| CVE-2026-65888 | CRITICAL | 9.8 | 0.2% | Jul 29, 2026 | Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows acto... |
| CVE-2026-65887 | CRITICAL | 9.8 | 0.2% | Jul 29, 2026 | Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method... |
| CVE-2026-65886 | HIGH | 7.5 | 0.4% | Jul 29, 2026 | Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unaut... |
| CVE-2026-59247 | HIGH | 7.6 | 0.1% | Jul 29, 2026 | Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute fo... |
| CVE-2026-54666 | HIGH | 8.3 | 0.3% | Jul 29, 2026 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/sch... |
| CVE-2026-54664 | HIGH | 8.3 | 0.3% | Jul 29, 2026 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/sch... |
| CVE-2026-54663 | MEDIUM | 6.1 | 0.2% | Jul 29, 2026 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol... |
| CVE-2026-54662 | HIGH | 8.3 | 0.3% | Jul 29, 2026 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-... |
| CVE-2026-54661 | HIGH | 8.3 | 0.3% | Jul 29, 2026 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templat... |
| CVE-2026-54660 | HIGH | 7.4 | 0.2% | Jul 29, 2026 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol... |
| CVE-2026-12703 | HIGH | 8 | 0.2% | Jul 29, 2026 | TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenti... |
| CVE-2026-9177 | CRITICAL | 9.4 | 0.3% | Jul 29, 2026 | A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway Se... |
