CVE Vulnerability Database
Search and browse 383,916 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28932 | MEDIUM | 5.5 | 0.1% | Jul 27, 2026 | A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is f... |
| CVE-2026-28931 | HIGH | 8.8 | 0.2% | Jul 27, 2026 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Ta... |
| CVE-2026-28928 | CRITICAL | 9.8 | 0.2% | Jul 27, 2026 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, m... |
| CVE-2026-28926 | HIGH | 7 | 0.1% | Jul 27, 2026 | A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 1... |
| CVE-2026-28912 | HIGH | 7.8 | 0.2% | Jul 27, 2026 | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.7... |
| CVE-2026-28911 | CRITICAL | 9.8 | 0.3% | Jul 27, 2026 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A m... |
| CVE-2026-28900 | MEDIUM | 5.5 | 0.1% | Jul 27, 2026 | A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma... |
| CVE-2026-28896 | HIGH | 7.7 | 0.1% | Jul 27, 2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15... |
| CVE-2026-28849 | MEDIUM | 5.5 | 0.1% | Jul 27, 2026 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Ta... |
| CVE-2026-20672 | MEDIUM | 5.5 | 0.1% | Jul 27, 2026 | An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7.... |
| CVE-2026-12001 | MEDIUM | 5.2 | 0.2% | Jul 27, 2026 | A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-... |
| CVE-2026-66018 | MEDIUM | 6.5 | 0.2% | Jul 27, 2026 | Build readers can access another repository's environment properties. A caller with read access to an ordinary repositor... |
| CVE-2026-66015 | HIGH | 7.2 | 0.3% | Jul 27, 2026 | An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account c... |
| CVE-2026-66014 | CRITICAL | 9.8 | 0.3% | Jul 27, 2026 | JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific condi... |
| CVE-2026-65925 | MEDIUM | 6.5 | 0.2% | Jul 27, 2026 | A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and ret... |
| CVE-2026-65924 | MEDIUM | 6.5 | 0.2% | Jul 27, 2026 | JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (... |
| CVE-2026-65923 | MEDIUM | 6.8 | 0.2% | Jul 27, 2026 | A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository... |
| CVE-2026-65922 | MEDIUM | 5.4 | 0.2% | Jul 27, 2026 | An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository acc... |
| CVE-2026-65921 | HIGH | 8.8 | 0.4% | Jul 27, 2026 | A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written ou... |
| CVE-2026-65618 | MEDIUM | 6.5 | 0.2% | Jul 27, 2026 | Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized ... |
| CVE-2026-65617 | HIGH | 8.8 | 0.3% | Jul 27, 2026 | A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentia... |
| CVE-2026-65616 | HIGH | 8.8 | 0.2% | Jul 27, 2026 | Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administra... |
| CVE-2026-64649 | MEDIUM | 6.5 | 0.6% | Jul 27, 2026 | Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 thr... |
| CVE-2026-64648 | MEDIUM | 5.4 | 0.5% | Jul 27, 2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr... |
| CVE-2026-59729 | MEDIUM | 5.1 | 0.3% | Jul 27, 2026 | Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped sp... |
