CVE Vulnerability Database
Search and browse 383,919 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-64649 | MEDIUM | 6.5 | 0.6% | Jul 27, 2026 | Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 thr... |
| CVE-2026-64648 | MEDIUM | 5.4 | 0.5% | Jul 27, 2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr... |
| CVE-2026-59729 | MEDIUM | 5.1 | 0.3% | Jul 27, 2026 | Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped sp... |
| CVE-2026-59727 | LOW | 2.1 | 0.3% | Jul 27, 2026 | Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a transition:persist, trans... |
| CVE-2026-56748 | HIGH | 8.8 | 0.6% | Jul 27, 2026 | Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authe... |
| CVE-2026-56747 | HIGH | 8.8 | 0.4% | Jul 27, 2026 | Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a r... |
| CVE-2026-42017 | HIGH | 8.8 | 0.3% | Jul 27, 2026 | An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged use... |
| CVE-2026-42016 | HIGH | 8.8 | 0.2% | Jul 27, 2026 | JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a valida... |
| CVE-2026-66759 | HIGH | 7.1 | 0.3% | Jul 27, 2026 | A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the pl... |
| CVE-2026-66758 | HIGH | 7.8 | 0.1% | Jul 27, 2026 | A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory alloca... |
| CVE-2026-66757 | MEDIUM | 5.5 | 0.1% | Jul 27, 2026 | A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memor... |
| CVE-2026-66031 | MEDIUM | 5.4 | 0.2% | Jul 27, 2026 | Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent... |
| CVE-2026-64647 | MEDIUM | 5.4 | 0.5% | Jul 27, 2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr... |
| CVE-2026-64646 | MEDIUM | 5.3 | 0.5% | Jul 27, 2026 | Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 thr... |
| CVE-2026-51244 | — | — | 0.3% | Jul 27, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-17612 | MEDIUM | 6.9 | — | Jul 27, 2026 | Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains... |
| CVE-2026-16481 | HIGH | 8.4 | 0.2% | Jul 27, 2026 | A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch... |
| CVE-2026-12383 | HIGH | 7.5 | 0.1% | Jul 27, 2026 | A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access control... |
| CVE-2026-10683 | MEDIUM | 4.6 | 0.1% | Jul 27, 2026 | In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating in target/slave mode, the rx_full interrupt handl... |
| CVE-2026-10682 | HIGH | 7.8 | 0.1% | Jul 27, 2026 | The userspace verifier z_vrfy_log_filter_set() for the log_filter_set syscall in subsys/logging/log_mgmt.c performed a s... |
| CVE-2026-66030 | MEDIUM | 5.4 | 0.2% | Jul 27, 2026 | Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authen... |
| CVE-2026-66029 | MEDIUM | 5.4 | 0.2% | Jul 27, 2026 | Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent... |
| CVE-2026-66028 | HIGH | 7.1 | 0.3% | Jul 27, 2026 | Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authe... |
| CVE-2026-64645 | MEDIUM | 6.1 | 1.0% | Jul 27, 2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr... |
| CVE-2026-64644 | MEDIUM | 5.3 | 0.5% | Jul 27, 2026 | Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 thr... |
