CVE Vulnerability Database
Search and browse 384,213 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-64210 | HIGH | 7.5 | 0.3% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix unlocked writing to ICOSQ Duri... |
| CVE-2026-64209 | HIGH | 7.1 | 0.2% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usbc: Fix out-of-bounds array access... |
| CVE-2026-64208 | HIGH | 7.5 | 0.4% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-ver... |
| CVE-2026-17039 | LOW | 3.1 | — | Jul 24, 2026 | A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based autho... |
| CVE-2026-8789 | HIGH | 8.1 | — | Jul 24, 2026 | The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit... |
| CVE-2026-8308 | MEDIUM | 6.1 | — | Jul 24, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Softwa... |
| CVE-2026-7007 | MEDIUM | 4.6 | 0.2% | Jul 24, 2026 | The Zephyr ext2 file system validates the on-disk superblock in ext2_verify_disk_superblock() (subsys/fs/ext2/ext2_impl.... |
| CVE-2026-66007 | MEDIUM | 6.5 | 0.5% | Jul 24, 2026 | Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builder... |
| CVE-2026-66006 | MEDIUM | 6.9 | 0.3% | Jul 24, 2026 | lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs... |
| CVE-2026-66005 | MEDIUM | 6.3 | 0.2% | Jul 24, 2026 | Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that ... |
| CVE-2026-66004 | MEDIUM | 6 | 0.3% | Jul 24, 2026 | BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that all... |
| CVE-2026-58630 | CRITICAL | 9.8 | 0.8% | Jul 24, 2026 | Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-58586 | CRITICAL | 9.8 | 0.4% | Jul 24, 2026 | Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the sys... |
| CVE-2026-57106 | CRITICAL | 10 | 0.9% | Jul 24, 2026 | Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-56163 | CRITICAL | 10 | 0.9% | Jul 24, 2026 | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el... |
| CVE-2026-55732 | HIGH | 8.7 | 0.3% | Jul 24, 2026 | Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-R... |
| CVE-2026-55731 | MEDIUM | 6.6 | 0.3% | Jul 24, 2026 | Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI... |
| CVE-2026-55730 | HIGH | 8.7 | 0.4% | Jul 24, 2026 | Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenti... |
| CVE-2026-55729 | HIGH | 7.7 | 0.3% | Jul 24, 2026 | Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all pla... |
| CVE-2026-55728 | LOW | 3.8 | 0.1% | Jul 24, 2026 | Stack-based Buffer Overflow (CWE-121) in `/usr/bin/ltsudo` `cmd_ipaddr_conflict` in Loytec LIP-ME201C, L-INX, L-GATE, L... |
| CVE-2026-49326 | MEDIUM | 6.5 | 0.2% | Jul 24, 2026 | Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest... |
| CVE-2026-17059 | MEDIUM | 6.5 | 0.2% | Jul 24, 2026 | A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloa... |
| CVE-2026-16802 | MEDIUM | 6.5 | 0.1% | Jul 24, 2026 | Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and ear... |
| CVE-2026-16801 | HIGH | 8.8 | 0.3% | Jul 24, 2026 | Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2... |
| CVE-2026-16800 | HIGH | 8.8 | 0.3% | Jul 24, 2026 | Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 20... |
