CVE Vulnerability Database
Search and browse 384,318 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45811 | HIGH | 7.5 | — | Jul 24, 2026 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket tr... |
| CVE-2026-16743 | MEDIUM | 5.5 | — | Jul 24, 2026 | A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root ... |
| CVE-2026-16730 | MEDIUM | 5.5 | 0.1% | Jul 24, 2026 | A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer set... |
| CVE-2026-15810 | HIGH | 8.7 | 0.3% | Jul 24, 2026 | A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.6... |
| CVE-2026-15243 | HIGH | 7.4 | 0.2% | Jul 24, 2026 | Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches th... |
| CVE-2026-10610 | HIGH | 8.5 | 0.1% | Jul 24, 2026 | Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user. |
| CVE-2026-7483 | HIGH | 8.5 | 0.1% | Jul 24, 2026 | Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a... |
| CVE-2026-16634 | CRITICAL | 9.8 | 0.2% | Jul 24, 2026 | TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is ... |
| CVE-2026-15663 | MEDIUM | 4.9 | 0.5% | Jul 24, 2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injecti... |
| CVE-2026-15401 | HIGH | 7.2 | 0.6% | Jul 24, 2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbf... |
| CVE-2026-10033 | HIGH | 7.3 | 0.3% | Jul 24, 2026 | The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,... |
| CVE-2026-63317 | MEDIUM | 5.6 | 0.3% | Jul 24, 2026 | Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected:... |
| CVE-2026-56392 | LOW | 1.8 | 0.1% | Jul 24, 2026 | GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation... |
| CVE-2026-56391 | MEDIUM | 4.6 | 0.1% | Jul 24, 2026 | GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--ch... |
| CVE-2026-49745 | HIGH | 7.8 | 0.1% | Jul 24, 2026 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ... |
| CVE-2026-49744 | HIGH | 7.8 | 0.1% | Jul 24, 2026 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ... |
| CVE-2026-49743 | HIGH | 7.8 | 0.1% | Jul 24, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of... |
| CVE-2026-24727 | CRITICAL | 9.3 | 0.7% | Jul 24, 2026 | An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporat... |
| CVE-2026-15821 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2026-15739 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' ... |
| CVE-2026-15704 | CRITICAL | 9.8 | 0.4% | Jul 24, 2026 | In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authori... |
| CVE-2026-15346 | MEDIUM | 6.1 | 0.3% | Jul 24, 2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '... |
| CVE-2026-12702 | MEDIUM | 4.9 | 0.2% | Jul 24, 2026 | In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to... |
| CVE-2026-16910 | MEDIUM | 5.5 | 0.2% | Jul 24, 2026 | A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers acc... |
| CVE-2026-16519 | HIGH | 7.3 | 0.1% | Jul 24, 2026 | A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads on... |
