CVE Vulnerability Database
Search and browse 384,213 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16799 | MEDIUM | 5 | 0.2% | Jul 24, 2026 | Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and ... |
| CVE-2026-16798 | MEDIUM | 6.5 | 0.2% | Jul 24, 2026 | Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.... |
| CVE-2026-12504 | HIGH | 8.4 | 0.1% | Jul 24, 2026 | Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-... |
| CVE-2026-12503 | CRITICAL | 9.2 | 0.1% | Jul 24, 2026 | Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-... |
| CVE-2026-12502 | HIGH | 8.4 | 0.1% | Jul 24, 2026 | Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, ... |
| CVE-2026-12496 | HIGH | 8.7 | 0.4% | Jul 24, 2026 | Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-I... |
| CVE-2026-17048 | MEDIUM | 4.9 | 0.2% | Jul 24, 2026 | A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs w... |
| CVE-2026-9765 | HIGH | 7.1 | 0.3% | Jul 24, 2026 | Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are ... |
| CVE-2026-7484 | MEDIUM | 5.3 | — | Jul 24, 2026 | External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Fu... |
| CVE-2026-66144 | HIGH | 7.5 | 0.3% | Jul 24, 2026 | Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the ... |
| CVE-2026-66143 | HIGH | 7.5 | 0.3% | Jul 24, 2026 | It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2... |
| CVE-2026-66142 | HIGH | 7.5 | 0.3% | Jul 24, 2026 | Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested s... |
| CVE-2026-66010 | MEDIUM | 6.1 | 0.2% | Jul 24, 2026 | DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDL... |
| CVE-2026-66009 | MEDIUM | 6.3 | 0.3% | Jul 24, 2026 | Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages... |
| CVE-2026-66008 | MEDIUM | 6.3 | 0.3% | Jul 24, 2026 | Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target cla... |
| CVE-2026-46452 | MEDIUM | 5.3 | — | Jul 24, 2026 | Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken dat... |
| CVE-2026-45816 | HIGH | 7.5 | — | Jul 24, 2026 | NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asser... |
| CVE-2026-45815 | HIGH | 7.5 | — | Jul 24, 2026 | Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_... |
| CVE-2026-45813 | HIGH | 8.8 | — | Jul 24, 2026 | Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper valida... |
| CVE-2026-45812 | MEDIUM | 6.5 | — | Jul 24, 2026 | Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event.... |
| CVE-2026-45811 | HIGH | 7.5 | — | Jul 24, 2026 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket tr... |
| CVE-2026-16743 | MEDIUM | 5.5 | — | Jul 24, 2026 | A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root ... |
| CVE-2026-16730 | MEDIUM | 5.5 | 0.1% | Jul 24, 2026 | A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer set... |
| CVE-2026-15810 | HIGH | 8.7 | 0.3% | Jul 24, 2026 | A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.6... |
| CVE-2026-15243 | HIGH | 7.4 | 0.2% | Jul 24, 2026 | Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches th... |
