CVE Vulnerability Database
Search and browse 384,300 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57106 | CRITICAL | 10 | 0.9% | Jul 24, 2026 | Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-56163 | CRITICAL | 10 | 0.9% | Jul 24, 2026 | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el... |
| CVE-2026-55732 | HIGH | 8.7 | 0.3% | Jul 24, 2026 | Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-R... |
| CVE-2026-55731 | MEDIUM | 6.6 | 0.3% | Jul 24, 2026 | Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI... |
| CVE-2026-55730 | HIGH | 8.7 | 0.4% | Jul 24, 2026 | Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenti... |
| CVE-2026-55729 | HIGH | 7.7 | 0.3% | Jul 24, 2026 | Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all pla... |
| CVE-2026-55728 | LOW | 3.8 | 0.1% | Jul 24, 2026 | Stack-based Buffer Overflow (CWE-121) in `/usr/bin/ltsudo` `cmd_ipaddr_conflict` in Loytec LIP-ME201C, L-INX, L-GATE, L... |
| CVE-2026-49326 | MEDIUM | 6.5 | 0.2% | Jul 24, 2026 | Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest... |
| CVE-2026-17059 | MEDIUM | 6.5 | 0.2% | Jul 24, 2026 | A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloa... |
| CVE-2026-16802 | MEDIUM | 6.5 | 0.1% | Jul 24, 2026 | Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and ear... |
| CVE-2026-16801 | HIGH | 8.8 | 0.3% | Jul 24, 2026 | Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2... |
| CVE-2026-16800 | HIGH | 8.8 | 0.3% | Jul 24, 2026 | Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 20... |
| CVE-2026-16799 | MEDIUM | 5 | 0.2% | Jul 24, 2026 | Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and ... |
| CVE-2026-16798 | MEDIUM | 6.5 | 0.2% | Jul 24, 2026 | Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.... |
| CVE-2026-12504 | HIGH | 8.4 | 0.1% | Jul 24, 2026 | Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-... |
| CVE-2026-12503 | CRITICAL | 9.2 | 0.1% | Jul 24, 2026 | Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-... |
| CVE-2026-12502 | HIGH | 8.4 | 0.1% | Jul 24, 2026 | Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, ... |
| CVE-2026-12496 | HIGH | 8.7 | 0.4% | Jul 24, 2026 | Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-I... |
| CVE-2026-17048 | MEDIUM | 4.9 | 0.2% | Jul 24, 2026 | A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs w... |
| CVE-2026-9765 | HIGH | 7.1 | 0.3% | Jul 24, 2026 | Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are ... |
| CVE-2026-7484 | MEDIUM | 5.3 | — | Jul 24, 2026 | External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Fu... |
| CVE-2026-66144 | HIGH | 7.5 | 0.3% | Jul 24, 2026 | Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the ... |
| CVE-2026-66143 | HIGH | 7.5 | 0.3% | Jul 24, 2026 | It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2... |
| CVE-2026-66142 | HIGH | 7.5 | 0.3% | Jul 24, 2026 | Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested s... |
| CVE-2026-66010 | MEDIUM | 6.1 | 0.2% | Jul 24, 2026 | DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDL... |
