CVE Vulnerability Database
Search and browse 384,058 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-64258 | MEDIUM | 5.5 | 0.2% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: fuse-uring: remove request-less entries from ent_w_... |
| CVE-2026-64257 | CRITICAL | 9.1 | 0.7% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2 ... |
| CVE-2026-64256 | MEDIUM | 5.5 | 0.2% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfs: don't wrap around quota ids in dqiterate LOLL... |
| CVE-2026-16766 | CRITICAL | 9.8 | 1.3% | Jul 25, 2026 | Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. ... |
| CVE-2026-15425 | MEDIUM | 6.4 | 0.2% | Jul 25, 2026 | The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-... |
| CVE-2026-14955 | MEDIUM | 6.5 | 0.5% | Jul 25, 2026 | The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all version... |
| CVE-2026-10818 | HIGH | 8.1 | 0.4% | Jul 25, 2026 | The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1... |
| CVE-2026-66374 | HIGH | 8.1 | 0.4% | Jul 25, 2026 | Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) rece... |
| CVE-2026-66373 | HIGH | 7.5 | 0.5% | Jul 25, 2026 | Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code executio... |
| CVE-2026-66339 | MEDIUM | 6.5 | 0.2% | Jul 24, 2026 | A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches t... |
| CVE-2026-66338 | HIGH | 7.2 | 0.2% | Jul 24, 2026 | A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes tha... |
| CVE-2026-66337 | MEDIUM | 6.5 | 0.2% | Jul 24, 2026 | A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes ... |
| CVE-2026-61892 | HIGH | 8.8 | 0.3% | Jul 24, 2026 | Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges. |
| CVE-2026-61886 | HIGH | 7.1 | 0.2% | Jul 24, 2026 | Weintek cMT3092X HMI stores user account passwords in plaintext. |
| CVE-2026-60135 | HIGH | 7.1 | 0.2% | Jul 24, 2026 | An attacker can modify data that should be restricted to read‑only access. |
| CVE-2026-60134 | HIGH | 8.8 | 0.3% | Jul 24, 2026 | Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges. |
| CVE-2026-16280 | CRITICAL | 9.8 | 0.3% | Jul 24, 2026 | An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computa... |
| CVE-2026-61884 | CRITICAL | 9.8 | 0.7% | Jul 24, 2026 | The web management interface of Tycon Systems TPDIN-Monitor-WEB2 does not perform server-side validation of credential... |
| CVE-2026-55985 | MEDIUM | 5.3 | 0.1% | Jul 24, 2026 | The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext o... |
| CVE-2025-71408 | HIGH | 8.5 | 0.2% | Jul 24, 2026 | NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations m... |
| CVE-2026-66041 | HIGH | 7.8 | 0.4% | Jul 24, 2026 | FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc fil... |
| CVE-2026-66040 | HIGH | 8.8 | 0.5% | Jul 24, 2026 | FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and A... |
| CVE-2026-66039 | HIGH | 7.8 | 0.4% | Jul 24, 2026 | FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decod... |
| CVE-2026-66038 | MEDIUM | 6.5 | 0.3% | Jul 24, 2026 | FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video de... |
| CVE-2026-66037 | MEDIUM | 5.5 | 0.3% | Jul 24, 2026 | FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF d... |
