CVE Vulnerability Database
Search and browse 383,946 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-43871 | HIGH | 7.5 | — | Jul 27, 2026 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.... |
| CVE-2026-41608 | HIGH | 7.5 | 1.1% | Jul 27, 2026 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This i... |
| CVE-2026-14856 | MEDIUM | 6.3 | — | Jul 27, 2026 | A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter ... |
| CVE-2026-12495 | MEDIUM | 5.3 | — | Jul 27, 2026 | Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys M... |
| CVE-2026-40000 | LOW | 1.8 | 0.3% | Jul 27, 2026 | The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compre... |
| CVE-2026-17534 | MEDIUM | 5.5 | — | Jul 27, 2026 | Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal ... |
| CVE-2026-17527 | HIGH | 7.7 | 0.3% | Jul 27, 2026 | In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only acc... |
| CVE-2026-17523 | HIGH | 7.8 | 0.1% | Jul 27, 2026 | A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, where an unprivileged local user can exploit this vul... |
| CVE-2026-65765 | MEDIUM | 6.9 | — | Jul 27, 2026 | Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper limitation of paths... |
| CVE-2026-65764 | MEDIUM | 5.1 | — | Jul 27, 2026 | Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user i... |
| CVE-2026-16554 | MEDIUM | 5.1 | 0.2% | Jul 27, 2026 | cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. Th... |
| CVE-2026-15799 | — | — | — | Jul 27, 2026 | Rejected reason: This is a duplicate. |
| CVE-2026-65894 | HIGH | 8.7 | — | Jul 27, 2026 | This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacke... |
| CVE-2026-65893 | HIGH | 7 | — | Jul 27, 2026 | This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An atta... |
| CVE-2026-64536 | HIGH | 8.1 | 0.3% | Jul 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in is_ap_in_tkip(... |
| CVE-2026-64535 | CRITICAL | 9.8 | 0.5% | Jul 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch S... |
| CVE-2026-64534 | CRITICAL | 9.8 | 0.4% | Jul 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_unini... |
| CVE-2026-64533 | HIGH | 7.8 | 0.1% | Jul 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate lcns_follow in log_replay conver... |
| CVE-2026-64532 | HIGH | 7.8 | 0.1% | Jul 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound NTFS_DE view.data_off in UpdateReco... |
| CVE-2026-64531 | HIGH | 7.8 | 0.1% | Jul 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action at... |
| CVE-2026-14837 | HIGH | 8.5 | 0.1% | Jul 27, 2026 | Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism... |
| CVE-2026-9830 | HIGH | 8.2 | — | Jul 27, 2026 | The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission cal... |
| CVE-2026-66412 | HIGH | 7.1 | 0.2% | Jul 27, 2026 | Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read mileston... |
| CVE-2026-14827 | MEDIUM | 6.8 | — | Jul 27, 2026 | The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it in... |
| CVE-2026-14820 | MEDIUM | 5.3 | — | Jul 27, 2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-log... |
