CVE Vulnerability Database
Search and browse 375,982 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44763 | HIGH | 7.6 | 0.3% | Aug 11, 2026 | SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation... |
| CVE-2026-44762 | LOW | 3.7 | 0.1% | Aug 11, 2026 | SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks c... |
| CVE-2026-44758 | CRITICAL | 9.1 | 0.5% | Aug 11, 2026 | SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted... |
| CVE-2026-40130 | MEDIUM | 5.3 | 0.4% | Aug 11, 2026 | SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated atta... |
| CVE-2026-34265 | CRITICAL | 9.8 | 0.4% | Aug 11, 2026 | SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol pars... |
| CVE-2026-8718 | HIGH | 8.4 | 0.1% | Aug 10, 2026 | tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, T... |
| CVE-2026-48161 | CRITICAL | 9.3 | 0.4% | Aug 10, 2026 | react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contain... |
| CVE-2026-11812 | LOW | 2.5 | 0.1% | Aug 10, 2026 | The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single fi... |
| CVE-2026-11811 | LOW | 3.7 | 0.3% | Aug 10, 2026 | The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS ... |
| CVE-2025-30241 | HIGH | 8.6 | 0.5% | Aug 10, 2026 | Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input pro... |
| CVE-2025-30240 | MEDIUM | 5.1 | 0.2% | Aug 10, 2026 | The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By ... |
| CVE-2025-30239 | HIGH | 8.5 | 0.1% | Aug 10, 2026 | In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive co... |
| CVE-2025-30238 | HIGH | 8.6 | 0.1% | Aug 10, 2026 | In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to e... |
| CVE-2025-30237 | HIGH | 8.7 | 0.2% | Aug 10, 2026 | The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not c... |
| CVE-2026-72919 | MEDIUM | 4.3 | 0.2% | Aug 10, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7... |
| CVE-2026-72918 | MEDIUM | 5.4 | 0.2% | Aug 10, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7... |
| CVE-2026-72917 | MEDIUM | 5.9 | 0.3% | Aug 10, 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti... |
| CVE-2026-72916 | MEDIUM | 6.3 | — | Aug 10, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-be... |
| CVE-2026-72915 | HIGH | 7.5 | 0.3% | Aug 10, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta... |
| CVE-2026-72914 | HIGH | 7.5 | 0.5% | Aug 10, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-be... |
| CVE-2026-6426 | MEDIUM | 4.4 | 0.2% | Aug 10, 2026 | A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size... |
| CVE-2025-32736 | MEDIUM | 4.9 | 0.2% | Aug 10, 2026 | Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may all... |
| CVE-2026-73035 | MEDIUM | 5.3 | 0.2% | Aug 10, 2026 | npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability t... |
| CVE-2026-73033 | HIGH | 7 | 0.6% | Aug 10, 2026 | Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmi... |
| CVE-2026-73030 | HIGH | 8.1 | 0.4% | Aug 10, 2026 | unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory func... |
