CVE Vulnerability Database
Search and browse 375,948 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15562 | HIGH | 7.5 | 0.4% | Aug 11, 2026 | A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and... |
| CVE-2026-15561 | HIGH | 7.5 | 0.3% | Aug 11, 2026 | A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an at... |
| CVE-2026-15560 | HIGH | 8.1 | 0.4% | Aug 11, 2026 | when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmars... |
| CVE-2026-15556 | HIGH | 8.1 | 0.2% | Aug 11, 2026 | A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching th... |
| CVE-2026-15555 | HIGH | 8.8 | 0.3% | Aug 11, 2026 | A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via ... |
| CVE-2026-15554 | HIGH | 7.4 | 0.2% | Aug 11, 2026 | the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authenti... |
| CVE-2026-10579 | CRITICAL | 9.8 | 0.4% | Aug 11, 2026 | A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no v... |
| CVE-2026-73156 | MEDIUM | 5.3 | 0.3% | Aug 11, 2026 | Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap t... |
| CVE-2026-73155 | MEDIUM | 5.3 | 0.3% | Aug 11, 2026 | Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first ... |
| CVE-2026-73140 | MEDIUM | 5.3 | 0.3% | Aug 11, 2026 | Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report ex... |
| CVE-2026-19519 | MEDIUM | 4.3 | 0.3% | Aug 11, 2026 | A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked... |
| CVE-2026-19418 | HIGH | 7.3 | 0.2% | Aug 11, 2026 | The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, wher... |
| CVE-2026-19518 | MEDIUM | 6.5 | 0.2% | Aug 11, 2026 | Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipu... |
| CVE-2026-19517 | MEDIUM | 6.5 | 0.2% | Aug 11, 2026 | Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerabilit... |
| CVE-2026-19391 | MEDIUM | 6.5 | 0.2% | Aug 11, 2026 | A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the ... |
| CVE-2026-16053 | HIGH | 8.5 | 1.0% | Aug 11, 2026 | Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Tr... |
| CVE-2026-8158 | MEDIUM | 5.3 | 0.2% | Aug 11, 2026 | The Signed Video Framework contained a buffer overflow issue which could lead the application using this framework to ... |
| CVE-2026-6505 | MEDIUM | 5.1 | 0.1% | Aug 11, 2026 | The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to priv... |
| CVE-2026-6181 | MEDIUM | 5.9 | 0.3% | Aug 11, 2026 | The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after... |
| CVE-2026-5304 | MEDIUM | 5.7 | 0.2% | Aug 11, 2026 | An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerabil... |
| CVE-2026-5303 | MEDIUM | 5.7 | 0.2% | Aug 11, 2026 | The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to priv... |
| CVE-2026-4757 | HIGH | 7.2 | 0.4% | Aug 11, 2026 | A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege... |
| CVE-2026-19516 | CRITICAL | 9.1 | 0.2% | Aug 11, 2026 | A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the graf... |
| CVE-2026-18348 | MEDIUM | 4.1 | 0.2% | Aug 11, 2026 | Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst... |
| CVE-2026-14549 | MEDIUM | 4.3 | 0.1% | Aug 11, 2026 | The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of ... |
