CVE Vulnerability Database
Search and browse 384,808 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-65699 | MEDIUM | 4.2 | — | Jul 23, 2026 | AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authentica... |
| CVE-2026-47769 | MEDIUM | 5.3 | — | Jul 23, 2026 | APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Pr... |
| CVE-2026-47755 | MEDIUM | 6.5 | 0.3% | Jul 23, 2026 | ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi... |
| CVE-2026-47752 | CRITICAL | 9.9 | — | Jul 23, 2026 | Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to S... |
| CVE-2026-47743 | HIGH | 8.7 | — | Jul 23, 2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed... |
| CVE-2026-47668 | CRITICAL | 10 | — | Jul 23, 2026 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/star... |
| CVE-2026-44210 | CRITICAL | 9.9 | 0.3% | Jul 23, 2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th... |
| CVE-2026-65761 | CRITICAL | 9.3 | — | Jul 23, 2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validat... |
| CVE-2026-65760 | CRITICAL | 9.2 | — | Jul 23, 2026 | Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0... |
| CVE-2026-65759 | HIGH | 8.7 | — | Jul 23, 2026 | Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical... |
| CVE-2026-65698 | MEDIUM | 6 | 0.3% | Jul 23, 2026 | Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjace... |
| CVE-2026-65697 | MEDIUM | 6.1 | — | Jul 23, 2026 | Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that... |
| CVE-2026-65696 | MEDIUM | 5.4 | — | Jul 23, 2026 | Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscrip... |
| CVE-2026-65695 | HIGH | 7.6 | — | Jul 23, 2026 | Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attacker... |
| CVE-2026-44909 | HIGH | 7.5 | — | Jul 23, 2026 | Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticate... |
| CVE-2026-16768 | MEDIUM | 5.3 | 0.2% | Jul 23, 2026 | A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined pale... |
| CVE-2026-65917 | HIGH | 8.8 | 0.4% | Jul 23, 2026 | CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in ... |
| CVE-2026-65916 | HIGH | 8.1 | — | Jul 23, 2026 | CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCre... |
| CVE-2026-48539 | MEDIUM | 5.4 | — | Jul 23, 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report conf... |
| CVE-2026-48538 | MEDIUM | 5.4 | — | Jul 23, 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configurat... |
| CVE-2026-48537 | MEDIUM | 5.4 | — | Jul 23, 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configurati... |
| CVE-2026-48536 | MEDIUM | 5.4 | — | Jul 23, 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuratio... |
| CVE-2026-48535 | MEDIUM | 5.4 | 0.1% | Jul 23, 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configurati... |
| CVE-2026-48534 | MEDIUM | 5.4 | — | Jul 23, 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that all... |
| CVE-2026-48533 | — | — | — | Jul 23, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
